CVE-2026-84901
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Sep 05, 2026
Vendor
unknown
Description
The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy terms they should not be able to manage.