WP Clinic
Log in Sign up

CVE

CVE-2025-47539 — Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) [wp-event-solution] < 4.0.27

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-47539 Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) [wp-event-solution] < 4.0.27 Incorrect Privilege Assignment Unknown < 4.0.27 4.0.27 2025-05-07

CVE-2025-47539

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the import_items() function in all versions up to, and including, 4.0.26. This makes it possible for unauthenticated attackers to import users that can have the administrator role leading to privilege escalation.

Source: Wordfence

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.