PT-2026-1749 · Unknown+1 · Events Manager+3

Sarawut Poolkhet

·

Publicado

2026-01-09

·

Atualizado

2026-01-09

·

CVE-2025-14657

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress versions up to and including 4.0.51
Description The Eventin plugin for WordPress is susceptible to unauthorized data modification because of a missing capability check on the post settings function. This allows unauthenticated attackers to alter plugin settings. Additionally, inadequate input sanitization and output escaping of the etn primary color setting allows unauthenticated attackers to inject arbitrary web scripts that execute when a user accesses a page with Eventin styles loaded. The API endpoint is not specified. The vulnerable parameter is etn primary color.
Recommendations Versions prior to 4.0.51 should be updated.

Correção

LPE

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-14657

Produtos afetados

Events Manager
Event Tickets/Registration
Eventin
Events Calendar