


Perceptive Security
SOC/SIEM Consultancy

The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintex…
Published:
7 juli 2026 om 22:00:00
Alert date:
8 juli 2026 om 06:00:57
Source:
nvd.nist.gov
Web Technologies, Identity & Access
The Eventer plugin for WordPress (versions up to and including 4.4.2) contains an insecure password reset mechanism where a plaintext copy of the password reset key is stored in the `eventer_verification_code` user meta field in `wp_usermeta`. This plaintext key can be leveraged via the plugin's custom reset action to set a new password for any user account. When chained with a SQL Injection vulnerability (CVE-2026-9700), unauthenticated attackers can extract the reset key and fully take over any user account, including administrator accounts. The password reset functionality is limited to environments running PHP version 7.4 or below. This vulnerability poses a critical risk to WordPress sites using the affected plugin, potentially enabling full site compromise. No authentication is required to exploit this vulnerability when combined with the related SQL injection flaw.
Technical details
Mitigation steps:
Affected products:
Eventer WordPress Plugin 4.4.2 and below
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-9701
https://codecanyon.net/item/eventer-wordpress-event-manager-plugin/20972534
https://www.wordfence.com/threat-intel/vulnerabilities/id/bc656765-1eac-4a96-99e9-c22d64984923?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
