ZeroHour

CVE-2025-47539

large

Incorrect Privilege Assignment Allows Privilege Escalation in Eventin WordPress Plugin

CVSS 3.1
9.8 critical
EPSS
28%p98
Published
()
Modified
AI analysis

Eventin, a WordPress events-management plugin developed by Arraytics (listed under the ThemeWinter vendor as plugin slug wp-event-solution), contains an incorrect privilege assignment flaw (CWE-266) that allows attackers to escalate privileges. Per the CVSS 3.1 vector, exploitation is possible over the network without authentication and without user interaction (AV:N/AC:L/PR:N/UI:N), though no public proof-of-concept documents the exact trigger point. A successful attacker gains elevated privileges on the affected WordPress site, such as the ability to create or modify privileged user accounts, with high impact on confidentiality, integrity, and availability. Any WordPress site running Eventin in any version up to and including 4.0.26 is affected. Exploitation has not been confirmed in the wild and there is no public PoC, but the EPSS score assigns a 27.9% probability of exploitation within 30 days (98th percentile), so defenders should treat this as likely to be targeted soon.

What to do: Update Eventin to the newest release beyond 4.0.26 via the WordPress plugin directory as soon as the patched version is available. Until then, audit the site's user list for unexpected administrator-level accounts and remove unknown users, since privilege-assignment flaws are commonly abused to plant backdoor admin accounts. Given the elevated EPSS (27.9% within 30 days), prioritize this patch across all sites where the wp-event-solution plugin is active, and monitor Arraytics/Patchstack advisories for the fixed version.

Affected
themewinter (Arraytics) Eventin (WordPress plugin wp-event-solution)All versions up to and including 4.0.26 (n/a through <= 4.0.26); no fixed version specified in the source data
Estimated exposure
large≈10,000+ sites (tens of thousands at most; WordPress.org lists 10,000+ active installs for the plugin) — Estimate derived from WordPress.org's public active-installation counter for the wp-event-solution plugin, which reports on the order of 10,000+ active installs, with each install representing one potentially affected WordPress site.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a through <= 4.0.26.

Vendors
themewinter
Products
eventin
Ecosystems
WordPress
Weakness
CWE-266
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news