{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3athemeficeventinwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:themefic:eventin:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-75983"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Eventin (\u003c= 4.1.23)"],"_cs_severities":["high"],"_cs_tags":["wordpress","privilege-escalation","plugin-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Themefic"],"content_html":"\u003cp\u003eThe Eventin - Event Calendar, Tickets, Registration, Booking \u0026amp; WooCommerce plugin for WordPress is vulnerable to a privilege escalation flaw (CVE-2026-75983) affecting all versions up to and including 4.1.23. The issue stems from the \u003ccode\u003ePermissionManager::manage_permissions()\u003c/code\u003e function, which is improperly registered as a callback to the WordPress \u003ccode\u003emap_meta_cap\u003c/code\u003e filter. This function unconditionally returns the 'exist' capability for any check performed against user ID 1, regardless of the specific capability requested.\u003c/p\u003e\n\u003cp\u003eThis vulnerability poses a significant risk to WordPress sites that have implemented security hardening by demoting the default user ID 1 from the Administrator role to a lower-privileged role (e.g., Subscriber). An attacker who gains control of the account associated with user ID 1 can effectively bypass all permission checks, enabling them to perform unauthorized administrative actions such as modifying site settings, promoting users, or installing arbitrary code via the plugin or theme editors. Sites where user ID 1 retains the default Administrator role remain at the same privilege level, as the bypass merely confirms existing administrative rights.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker possessing user ID 1 to achieve full administrative control over the target WordPress instance. This leads to total site takeover, potential data exfiltration, and the ability to execute arbitrary PHP code through administrative interfaces such as the theme or plugin editor. The vulnerability specifically targets environments where administrators have followed hardening practices by demoting the initial user account.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Eventin plugin to a version released after 4.1.23 to patch CVE-2026-75983.\u003c/li\u003e\n\u003cli\u003eReview all administrative accounts to ensure that user ID 1 is not assigned to a low-privileged account if it is not necessary for operation.\u003c/li\u003e\n\u003cli\u003eAudit WordPress user accounts to identify if any account assigned user ID 1 has been granted unexpected roles or if that ID has been compromised.\u003c/li\u003e\n\u003cli\u003eImplement file integrity monitoring on the WordPress \u003ccode\u003e/wp-content/plugins/\u003c/code\u003e and \u003ccode\u003e/wp-content/themes/\u003c/code\u003e directories to detect unauthorized code execution attempts following a potential privilege escalation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T07:39:32Z","date_published":"2026-09-15T07:39:32Z","id":"https://feed.craftedsignal.io/briefs/2026-09-eventin-privilege-escalation/","summary":"The Eventin WordPress plugin (\u003c= 4.1.23) contains a vulnerability that allows users with ID 1 to bypass capability checks and escalate privileges to administrator level.","title":"Privilege Escalation in Eventin WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-eventin-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:themefic:eventin:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}