Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-84905— Eventin < 4.1.24 - Contributor+ User Creation via Speaker Creation

Quick assessment

Affected
Unknown Eventin
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Eventin WordPress 插件 4.1.24 版本之前,当添加演讲者时,插件未验证用户是否具备创建账户的权限。这使得拥有“贡献者”(Contributor)及以上权限的用户能够创建新的 WordPress 用户账户,而这些新账户所拥有的权限超过了创建者自身的权限范围,包括发布内容和上传文件的权限。此外,攻击者可以通过提供一个自己控制的电子邮箱地址,获取该新建账户的有效登录凭证。

AI Predicted 8.8 Difficulty: Easy EPSS 0.17% · P7

Possible ATT&CK Techniques 1 AI

T1098.001 · Additional Cloud Credentials

Affected Version Matrix 1

VendorProduct Version RangeStatus
Unknown Eventin < 4.1.24 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-84905

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Eventin < 4.1.24 - Contributor+ User Creation via Speaker Creation
Source: CVE Program / CVE List V5
Vulnerability Description
The Eventin WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speaker, allowing users with contributor-level access and above to create new WordPress user accounts that carry capabilities beyond their own, including publishing content and uploading files, and, by supplying an email address they control, to obtain a working login to the created account.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown Eventin 0 ~ 4.1.24 -

II. Public POCs for CVE-2026-84905

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-84905

登录查看更多情报信息。

Other References for CVE-2026-84905 (1)

Same Patch Batch · Unknown · 2026-09-16 · 46 CVEs total

CVE-2026-13407 6.1 MEDIUM Royal Elementor Addons < 1.7.1067 - Unauthenticated Stored HTML Injection in Form Notifica
CVE-2026-84906 5.3 MEDIUM Eventin < 4.1.24 - Unauthenticated Payment Bypass via Stripe and PayPal Cross-Order Transa
CVE-2026-86475 5.3 MEDIUM Appointment Hour Booking < 1.5.95 - Unauthenticated Booking Capacity Bypass via Multi-Appo
CVE-2026-19857 4.8 MEDIUM Formidable Forms < 6.35 - Unauthenticated Arbitrary Shortcode Execution via [entry_key] Cu
CVE-2026-76552 WP Import Export Lite < 3.9.33 - Authenticated Arbitrary File Upload via Remote Image Impo
CVE-2026-85349 FluentBoards < 2.0.15 - Subscriber+ Private Board Membership Disclosure via IDOR
CVE-2026-76555 WP Import Export Lite < 3.9.33 - Authenticated Sensitive File Disclosure via Existing File
CVE-2026-76557 WP Import Export Lite < 3.9.33 - Authenticated SQLi via Import Options
CVE-2026-76551 WP Import Export Lite < 3.9.33 - Authenticated RCE via Export Field PHP Function
CVE-2026-74926 MultiVendorX 5.0.0 - 5.0.15 - Subscriber+ Arbitrary Store Data and Ownership Overwrite via
CVE-2026-76553 WP Import Export Lite < 3.9.33 - Authenticated Arbitrary Directory Deletion via Template P
CVE-2026-78472 Ni WooCommerce Sales Report < 4.2.0 - Unauthenticated SQLi via 'sort' Parameter
CVE-2026-82124 Schema & Structured Data for WP & AMP < 1.66 - Unauthenticated Password-Protected Post Con
CVE-2026-77702 Eventin < 4.1.24 - Unauthenticated Ticket Price Rewrite via order_token
CVE-2026-84829 Optimole < 4.2.12 - Unauthenticated Stored XSS via Srcset Descriptor Parameter
CVE-2026-84088 Xpro Elementor Addons < 1.7.9 - Contributor+ Stored XSS via Interactive Circle Widget
CVE-2026-82126 Schema & Structured Data for WP & AMP 1.63 - 1.65 - Contributor+ Non-Public Post Content D
CVE-2026-82125 Schema & Structured Data for WP & AMP 1.46 - 1.65 - Unauthenticated Non-Public Comment Con
CVE-2026-84907 Eventin < 4.1.24 - Unauthenticated Order and Attendee Status Reset via Payment REST Endpoi
CVE-2026-76550 WP Import Export Lite < 3.9.34 - Authenticated RCE via Export Template Path Traversal

Showing top 20 of 46 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-84905

No comments yet


Leave a comment