Loading market data...
← Back to CVE feed

CVE-2026-84901

UNKNOWN View on NVD ↗

Description

The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy terms they should not be able to manage.

Published: Sep 05, 2026 07:17 UTC Modified: Sep 05, 2026 07:17 UTC