CyberRota Analysis
AI-GeneratedThe Eventin plugin for WordPress is vulnerable to an authorization bypass, allowing authenticated users with subscriber-level access or higher to manipulate notification flow event automation workflows intended for administrators. This flaw can lead to unauthorized viewing, creation, updating, cloning, and deletion of sensitive event management data. WordPress site administrators using this plugin should prioritize patching to mitigate potential exploitation.
Original NVD Description
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to view, create, update, clone, and delete notification flow event automation workflows that should be restricted to administrators.