CVE-2025-47539
largeIncorrect Privilege Assignment Allows Privilege Escalation in Eventin WordPress Plugin
Eventin, a WordPress events-management plugin developed by Arraytics (listed under the ThemeWinter vendor as plugin slug wp-event-solution), contains an incorrect privilege assignment flaw (CWE-266) that allows attackers to escalate privileges. Per the CVSS 3.1 vector, exploitation is possible over the network without authentication and without user interaction (AV:N/AC:L/PR:N/UI:N), though no public proof-of-concept documents the exact trigger point. A successful attacker gains elevated privileges on the affected WordPress site, such as the ability to create or modify privileged user accounts, with high impact on confidentiality, integrity, and availability. Any WordPress site running Eventin in any version up to and including 4.0.26 is affected. Exploitation has not been confirmed in the wild and there is no public PoC, but the EPSS score assigns a 27.9% probability of exploitation within 30 days (98th percentile), so defenders should treat this as likely to be targeted soon.
What to do: Update Eventin to the newest release beyond 4.0.26 via the WordPress plugin directory as soon as the patched version is available. Until then, audit the site's user list for unexpected administrator-level accounts and remove unknown users, since privilege-assignment flaws are commonly abused to plant backdoor admin accounts. Given the elevated EPSS (27.9% within 30 days), prioritize this patch across all sites where the wp-event-solution plugin is active, and monitor Arraytics/Patchstack advisories for the fixed version.
| themewinter (Arraytics) Eventin (WordPress plugin wp-event-solution) | All versions up to and including 4.0.26 (n/a through <= 4.0.26); no fixed version specified in the source data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a through <= 4.0.26.
- Vendors
- themewinter
- Products
- eventin
- Ecosystems
- WordPress
- Weakness
- CWE-266
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H