CVE Database /
CVE-2025-14657
CVE · High
CVE-2025-14657 — Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.52
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-14657
|
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.52 |
Missing Authorization |
High
7.2
|
< 4.0.52
|
4.0.52 |
2026-01-08 |
—
|
CVE-2025-14657
The Eventin plugin for WordPress has a security flaw in all versions up to 4.0.51. This weakness allows anyone to alter the plugin's settings without needing permission, which can be exploited by malicious individuals. Additionally, when users view pages with Eventin styling, they may inadvertently run arbitrary web code due to inadequate protection against script injection on certain color setting inputs.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings