S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated May 27, 2025

CVE-2025-47539 Scanner

CVE-2025-47539 Scanner - Privilege Escalation vulnerability in Eventin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.4k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-47539
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a through <= 4.0.26.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Eventinby Arraytics
0
Updated Aug 22, 2026View on NVD →
Detail

Eventin is a popular WordPress plugin used for event management, offering features like ticketing, registration, and scheduling for various types of events. It is commonly utilized by small-to-medium enterprises, event managers, and individuals needing to manage and display events on their WordPress sites. The plugin aims at simplifying event setups, offering an easy user interface and integration with other tools, available to anyone with a WordPress site needing advanced event management capabilities. This wide applicability means that the platform can empower users to manage complex event logistics simply. With its ease of use, Eventin has become quite a popular choice for non-technical users as well.

The vulnerability detected in this Version of Eventin allows unauthenticated users to escalate privileges through a REST API endpoint that lacks proper permission checks. This vulnerability allows attackers to potentially import users into WordPress with arbitrary roles, including higher-level roles like an administrator. The oversight, if exploited, could result in a full compromise of the WordPress site. Privilege escalation vulnerabilities are critical as they can turn any authenticated session into one with full administrative access. The CVSS score of 9.8 highlights the severity and critical nature of this flaw in the plugin.

Technical details reveal that the endpoint vulnerable to this exploit is '/wp-json/eventin/v2/speakers/import?_locale=user'. An attacker can exploit this by sending a POST request with a JSON payload that specifies a user's role as 'administrator'. The core issue stems from a lack of authorization checks before processing user roles during import. The vulnerability primarily affects an endpoint designed for importing speaker data into the plugin. This missing validation allows the importation of users with escalated privileges, posing severe security risks.

Exploitation of this vulnerability could result in unauthorized users gaining administrative access to the WordPress site, leading to potential alterations of settings, addition of malicious plugins, or even complete takeover of the website. Further repercussions include data theft, introduction of backdoors, and usage of the platform for malicious activities like phishing campaigns. Any sensitive data present on or accessible through the site can be compromised, terribly affecting the site's users or owners.

REFERENCES

Solution Advice
  • Update the Eventin plugin to version 4.0.27 or later to mitigate this vulnerability.
  • Implement security best practices for REST API interactions including proper permission checks.
  • Regularly audit and review users' roles and permissions for any unauthorized changes.
  • Monitor logs for any unusual activity that could indicate exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.