The Eventin WordPress plugin before 4.1.21 does not...
Low severity
Unreviewed
Published
Aug 21, 2026
to the GitHub Advisory Database
•
Updated Aug 21, 2026
Description
Published by the National Vulnerability Database
Aug 21, 2026
Published to the GitHub Advisory Database
Aug 21, 2026
Last updated
Aug 21, 2026
The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify event ownership, allowing users with contributor-level access and above to trigger blind server-side requests to arbitrary hosts.
References