CyberRota Analysis
AI-GeneratedThe Eventin WordPress plugin prior to version 4.1.21 is vulnerable as it fails to properly verify user permissions when assigning roles and updating user metadata during speaker creation. This flaw allows users with contributor-level access and higher to modify roles and metadata of other users, potentially leading to unauthorized privilege escalation. WordPress site administrators and security teams should prioritize this vulnerability to prevent misuse of user roles and maintain proper access controls.
Original NVD Description
The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users with contributor-level access and above to modify other users' roles and metadata.