CVE-2026-9701 Details
Description
The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of the password reset key in the `eventer_verification_code` user meta field when a user requests a password reset. The plaintext key stored in `wp_usermeta` can be used with the plugin's custom reset action to set a new password for any user. Combined with another vulnerability such as SQL Injection (CVE-2026-9700), this makes it possible for unauthenticated attackers to extract the plaintext reset key and take over any user account, including administrators. Note: The password reset function only works up to PHP version 7.4.
A vulnerability exists in the Eventer plugin for WordPress, affecting all versions through 4.4.2, due to an insecure password reset mechanism. The plugin saves a plaintext password reset key in the 'eventer_verification_code' user meta field when a password reset is requested. This key can be exploited with the plugin's custom reset action to change the password for any user. When combined with another vulnerability, such as SQL Injection (CVE-2026-9700), it enables unauthenticated attackers to retrieve the plaintext reset key and take over any user account, including those of administrators. It is important to note that the password reset feature is only functional up to PHP version 7.4.
There is no known patch available for this vulnerability. It is recommended to review the vulnerability details thoroughly and consider uninstalling the affected plugin.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 8, 2026CISA-ADP
Assessed Jul 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://codecanyon.net/item/eventer-wordpress-event-manager-plugin/20972534 | [email protected] | Content WallProductVendor |
| https://www.wordfence.com/threat-intel/vulnerabilities/id/bc656765-1eac-4a96-99e9-c22d64984923?source=cve | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-289 | Authentication Bypass by Alternate Name | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Eventer | <= 4.4.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 8, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | New CVE Received | [email protected] |
Volerion