
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11821 is an authorization bypass vulnerability in the Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress, affecting all versions up to and including 4.1.17. The flaw allows authenticated attackers with subscriber-level access or above to perform administrative actions on notification flow event automation workflows without proper privilege verification. It was published on September 9, 2026, and assigned a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Wordfence).
The vulnerability is classified as CWE-862 (Missing Authorization) and stems from the plugin's failure to properly verify that a requesting user has sufficient privileges before executing actions on notification flow event automation workflows. The vulnerable code is located in FlowAPI.php (line 66) within the bundled themewinter/email-notification-sdk library, as evidenced by the difference between the 4.1.17 and 4.1.18 plugin tags. An authenticated attacker with a subscriber-level WordPress account can send crafted network requests to the plugin's API endpoints to view, create, update, clone, or delete admin-restricted automation workflows (GitHub Advisory, Wordfence).
Successful exploitation allows any authenticated WordPress user (subscriber-level or above) to fully manage notification flow event automation workflows that are intended to be restricted to administrators. This results in low confidentiality impact (unauthorized viewing of workflow configurations) and low integrity impact (unauthorized creation, modification, cloning, or deletion of workflows), with no direct availability impact. Tampering with event automation workflows could disrupt legitimate event notifications, introduce malicious notification logic, or expose sensitive workflow configuration data (GitHub Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at the time of disclosure. The vulnerability requires authentication (minimum subscriber-level account), which limits the attack surface compared to unauthenticated flaws. The EPSS score is 0.0, indicating a very low probability of exploitation in the near term, and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog (Wordfence, GitHub Advisory).
FlowAPI.php) by reviewing plugin source code or intercepting legitimate admin requests with a proxy tool such as Burp Suite.FlowAPI.php.flow, notification, or automation within the wp-event-solution plugin namespace).wp_options or plugin-specific tables) not attributable to administrator activity.FlowAPI endpoints from low-privilege user sessions, particularly outside normal administrative hours.Update the Eventin plugin to version 4.1.18 or later, which contains the authorization fix in FlowAPI.php (GitHub Advisory). As an interim workaround, restrict subscriber-level user registration on affected WordPress sites or disable the Eventin plugin until patching is complete. Administrators should also audit existing notification flow event automation workflows for any unauthorized modifications or additions made by non-administrator accounts (Wordfence).
The vulnerability was discovered and reported by Wordfence, which assigned the CVE and published the advisory on September 9, 2026. No notable independent researcher commentary or significant social media discussion has been observed beyond standard vulnerability aggregator coverage (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."