CyberRota Analysis
AI-GeneratedThe Eventin WordPress plugin prior to version 4.1.20 has a vulnerability that allows users with contributor-level access and higher to access and read stored personal data of other customers, including names and email addresses. This exposure of sensitive information could lead to privacy breaches and unauthorized data access. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential risks.
Original NVD Description
The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users with contributor-level access and above to read other customers' personal data such as names and email addresses.