The Eventin WordPress plugin before 4.0.27 suffers from an unauthenticated privilege escalation vulnerability. Due to a missing permission check in the a REST API endpoint, unauthenticated attackers can import users with arbitrary roles, including administrator, leading to full site compromise.
id: CVE-2025-47539
info:
name: Eventin <= 4.0.26 - Privilege Escalation
author: pdresearch
se
...