top of page
perceptive_background_267k.jpg

The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintex…

Published:

7 juli 2026 om 22:00:00

Alert date:

8 juli 2026 om 06:00:57

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

The Eventer plugin for WordPress (versions up to and including 4.4.2) contains an insecure password reset mechanism where a plaintext copy of the password reset key is stored in the `eventer_verification_code` user meta field in `wp_usermeta`. This plaintext key can be leveraged via the plugin's custom reset action to set a new password for any user account. When chained with a SQL Injection vulnerability (CVE-2026-9700), unauthenticated attackers can extract the reset key and fully take over any user account, including administrator accounts. The password reset functionality is limited to environments running PHP version 7.4 or below. This vulnerability poses a critical risk to WordPress sites using the affected plugin, potentially enabling full site compromise. No authentication is required to exploit this vulnerability when combined with the related SQL injection flaw.

Technical details

Mitigation steps:

Affected products:

Eventer WordPress Plugin 4.4.2 and below

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page