PT-2026-1749 · Unknown+1 · Events Manager+3

Sarawut Poolkhet

·

Published

2026-01-09

·

Updated

2026-01-09

·

CVE-2025-14657

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress versions up to and including 4.0.51
Description The Eventin plugin for WordPress is susceptible to unauthorized data modification because of a missing capability check on the post settings function. This allows unauthenticated attackers to alter plugin settings. Additionally, inadequate input sanitization and output escaping of the etn primary color setting allows unauthenticated attackers to inject arbitrary web scripts that execute when a user accesses a page with Eventin styles loaded. The API endpoint is not specified. The vulnerable parameter is etn primary color.
Recommendations Versions prior to 4.0.51 should be updated.

Fix

LPE

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-14657

Affected Products

Events Manager
Event Tickets/Registration
Eventin
Events Calendar