CyberRota Analysis
AI-GeneratedThe Eventin WordPress plugin prior to version 4.1.21 is vulnerable due to inadequate validation of user-supplied webhook URLs, enabling users with contributor-level access or higher to initiate blind server-side requests to arbitrary external hosts. This could lead to potential information leakage or further exploitation of the server. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify event ownership, allowing users with contributor-level access and above to trigger blind server-side requests to arbitrary hosts.