---
id: CVE-2026-84905
title: >-
  The Eventin  WordPress plugin before 4.1.24 does not verify a user's
  capability to create accounts when adding a speaker, allowing users with
  contributor-level access and above to create new WordPress user accounts that
  carry capabilitie…
summary: >-
  The Eventin  WordPress plugin before 4.1.24 does not verify a user's
  capability to create accounts when adding a speaker, allowing users with
  contributor-level access and above to create new WordPress user accounts that
  carry capabilitie…
severity: low
cvss: 2.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
product: Eventin
affected:
  - Eventin < 4.1.24
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T13:16:50.003'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84905'
references:
  - url: 'https://wpscan.com/vulnerability/6d3bfda2-351a-4700-9fd4-4c3101bfcd38/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T12:19:46.333341Z'
epss: 0.00281
epssPercentile: 0.18396
ingestedAt: '2026-09-16T06:51:06.249Z'
---

## Overview

The Eventin  WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speaker, allowing users with contributor-level access and above to create new WordPress user accounts that carry capabilities beyond their own, including publishing content and uploading files, and, by supplying an email address they control, to obtain a working login to the created account.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
