{"id":3569,"date":"2025-05-20T08:40:01","date_gmt":"2025-05-20T08:40:01","guid":{"rendered":"https:\/\/certera.com\/blog\/?p=3569"},"modified":"2025-05-20T08:40:02","modified_gmt":"2025-05-20T08:40:02","slug":"critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk","status":"publish","type":"post","link":"https:\/\/certera.com\/blog\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\/","title":{"rendered":"CVE-2025-47539: Critical Eventin WordPress Plugin Vulnerability Puts 10,000+ Sites at Risk\u00a0"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A severe zero-day vulnerability has been found in the widely used Eventin WordPress plugin (Themewinter), which puts over 10,000 websites at extreme risk for complete takeover. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CVE-2025-47539 is the identifier for the flaw, which permits unauthenticated privilege escalation, allowing users to create user accounts at the Administrator level without having access to WordPress before.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-cve-2025-47539-nbsp\">What is CVE-2025-47539?&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">CVE-2025-47539 is a REST API vulnerability, with a CVSS score of 9.8 (Critical). This vulnerability was discovered by Denver Jackson of the Patchstack Alliance and was responsibly disclosed through the Patchstack Zero Day Initiative, for which he received a $600 bug bounty.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The vulnerability exists in the REST API endpoint:&nbsp;<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code><em>\/wp-json\/eventin\/v2\/speakers\/import<\/em>&nbsp;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This endpoint is where users can import speaker data, typically from a CSV file. Because the permission check was flawed, the API had no way to restrict who can execute the import and create an administrator account.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-root-cause-incorrect-permission-callback-nbsp-nbsp\">Root Cause: Incorrect permission callback&nbsp;&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The permission_callback function which occurs as the import_item_permissions_check() function was callbacks intended to restrict access to connected users with the proper capabilities; <strong>however, it was designed:&nbsp;<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code><em>public function import_item_permissions_check($request) {<\/em>&nbsp;\n<em>return true;<\/em>&nbsp;\n<em>}<\/em>&nbsp;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This allows anyone on the Internet, including unauthenticated users, to trigger the import function.No authentication, validation, or access control \u2014 allowing attackers to upload maliciously-crafted CSV files.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-does-the-exploit-work\">How does the Exploit Work?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The attacker could exploit this vulnerability by crafting a POST request to the given endpoint and attaching a CSV file like this:&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>username,email,role<\/em>&nbsp;<br><em>attacker,attacker@example.com,administrator<\/em>&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The backend import system can process the file with:&nbsp;<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">$importer-&gt;import($file);&nbsp;<br>$this-&gt;create_speaker();&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Without access control or role validation in place by the plugin, the attacker could:&nbsp;<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Create a new admin user account.&nbsp;<\/li>\n\n\n\n<li>Reset the password (if so desired).&nbsp;<\/li>\n\n\n\n<li>Have full administrative control over the entire WordPress site.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This in short means that the entire site has been compromised \u2014 the site&#8217;s admin dashboard was now in the attackers&#8217; hands, including user details, user submissions, site files, and so forth.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-has-been-fixed-nbsp\">What Has Been Fixed?&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This vulnerability was patched in Eventin version 4.0.27. Among the key changes:&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Implementing a <strong>permission_callback function<\/strong>. In the permission callback function, they check that all users will have to be properly authenticated to access the import functionality.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A whitelist of user roles, so only roles on the established white list could be assigned on the import \u2014 this therefore means arbitrary admin or custom roles cannot be created.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-should-you-do-now-nbsp\">What Should You Do Now?&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">All administrators of any WordPress site that has the Eventin plugin installed should immediately take the following steps:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Update the <strong>plugin to 4.0.27 or higher<\/strong> from your dashboard or Themewinter&#8217;s official site.&nbsp;<\/li>\n\n\n\n<li>Check your <strong>user list for old or suspicious admin accounts<\/strong> that aren&#8217;t attributable to you or someone with appropriate access.&nbsp;&nbsp;<\/li>\n\n\n\n<li><strong>Change the passwords<\/strong> on all admin accounts to mitigate the possibility of hijacked admin accounts.&nbsp;<\/li>\n\n\n\n<li>Apply <a href=\"https:\/\/certera.com\/blog\/what-is-multi-factor-authentication-difference-between-2fa-mfa\/\">2FA (Two-Factor Authentication)<\/a> to admin accounts to reduce unauthorized access risk.&nbsp;<\/li>\n\n\n\n<li>Scrutinize your logs and security plugin for strange (and unusually frequent) POST requests to <strong>\/wp-json\/eventin\/v2\/speakers\/import<\/strong>.&nbsp;<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-lessons-for-plugin-developers-nbsp\">Lessons for Plugin Developers&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The entire incident should be a strong reminder for all WordPress developers&#8217; sake:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Do not use permission_callback functions that always return true.&nbsp;<\/li>\n\n\n\n<li>REST API endpoints should have capability checks (e.g. current_user_can(&#8216;manage_options&#8217;).).&nbsp;<\/li>\n\n\n\n<li>User import and user export features should validate roles, sanitize, and check who has permissions before acting.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Security checks are not security. Security checks on their faces, may offer initial protections, but even the most superficial checks are offering a false sense of security &#8211; full code audits, testing, and product review must be part of our product lifecycle.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-protect-your-wordpress-site-from-all-attacks-amp-vulnerabilities\">Protect Your WordPress Site from All Attacks &amp; Vulnerabilities<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/certera.com\/services\/wordpress-security\">WordPress Security Services<\/a> can protect you. Don&#8217;t wait for a breach before taking action! From malware removal and DDoS protection to real-time patching of vulnerabilities, <a href=\"https:\/\/certera.com\/sitelock\">SiteLock<\/a> will keep your website secure 24\/7. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Protect your business, protect your data, protect your reputation\u2014get started with WordPress protection today!&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A severe zero-day vulnerability has been found in the widely used Eventin WordPress plugin (Themewinter), which puts over 10,000 websites at extreme risk for complete takeover. CVE-2025-47539 is the identifier for the flaw, which permits unauthenticated privilege escalation, allowing users to create user accounts at the Administrator level without having access to WordPress before.&nbsp; What<span class=\"morelink d-block mt-3\"><a href=\"https:\/\/certera.com\/blog\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\/\">Read More<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":3574,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[32],"tags":[],"class_list":["post-3569","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-vulnerability","entry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v24.6 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Critical Eventin WordPress Plugin Vulnerability Puts 10k+ Sites at Risk<\/title>\n<meta name=\"description\" content=\"WordPress Eventin Plugin Vulnerability has put over 10,000 websites at serious risk. Patch now: 4.0.27. Checkout the recommendation actions.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/certera.com\/blog\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CVE-2025-47539: Critical Eventin WordPress Plugin Vulnerability Puts 10,000+ Sites at Risk\u00a0\" \/>\n<meta property=\"og:description\" content=\"WordPress Eventin Plugin Vulnerability has put over 10,000 websites at serious risk. Patch now: 4.0.27. Checkout the recommendation actions.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/certera.com\/blog\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\/\" \/>\n<meta property=\"og:site_name\" content=\"EncryptedFence by Certera - Web &amp; Cyber Security Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/certeraLLC\/\" \/>\n<meta property=\"article:published_time\" content=\"2025-05-20T08:40:01+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-05-20T08:40:02+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/05\/eventin-plugin-vulnerability.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"960\" \/>\n\t<meta property=\"og:image:height\" content=\"620\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Janki Mehta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@certera_llc\" \/>\n<meta name=\"twitter:site\" content=\"@certera_llc\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Janki Mehta\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\\\/\"},\"author\":{\"name\":\"Janki Mehta\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/person\\\/e5a476aa90d9e02260ebfe4b0bf046b7\"},\"headline\":\"CVE-2025-47539: Critical Eventin WordPress Plugin Vulnerability Puts 10,000+ Sites at Risk\u00a0\",\"datePublished\":\"2025-05-20T08:40:01+00:00\",\"dateModified\":\"2025-05-20T08:40:02+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\\\/\"},\"wordCount\":706,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/eventin-plugin-vulnerability.webp\",\"articleSection\":[\"Vulnerability\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/certera.com\\\/blog\\\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\\\/#respond\"]}],\"copyrightYear\":\"2025\",\"copyrightHolder\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\\\/\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\\\/\",\"name\":\"Critical Eventin WordPress Plugin Vulnerability Puts 10k+ Sites at Risk\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/eventin-plugin-vulnerability.webp\",\"datePublished\":\"2025-05-20T08:40:01+00:00\",\"dateModified\":\"2025-05-20T08:40:02+00:00\",\"description\":\"WordPress Eventin Plugin Vulnerability has put over 10,000 websites at serious risk. Patch now: 4.0.27. Checkout the recommendation actions.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/certera.com\\\/blog\\\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\\\/#primaryimage\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/eventin-plugin-vulnerability.webp\",\"contentUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/eventin-plugin-vulnerability.webp\",\"width\":960,\"height\":620,\"caption\":\"Critical Eventin Plugin Vulnerability\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/certera.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CVE-2025-47539: Critical Eventin WordPress Plugin Vulnerability Puts 10,000+ Sites at Risk\u00a0\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/\",\"name\":\"EncryptedFence by Certera - Web & Cyber Security Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\"},\"alternateName\":\"Certera's EncryptedFence Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/certera.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\",\"name\":\"Certera\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-encryptedfence.svg\",\"contentUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-encryptedfence.svg\",\"caption\":\"Certera\"},\"image\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/certeraLLC\\\/\",\"https:\\\/\\\/x.com\\\/certera_llc\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/certera-llc\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/person\\\/e5a476aa90d9e02260ebfe4b0bf046b7\",\"name\":\"Janki Mehta\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g\",\"caption\":\"Janki Mehta\"},\"description\":\"Janki Mehta is a passionate Cyber-Security Enthusiast who keenly monitors the latest developments in the Web\\\/Cyber Security industry. She puts her knowledge into practice and helps web users by arming them with the necessary security measures to stay safe in the digital world.\",\"sameAs\":[\"https:\\\/\\\/certerassl.com\\\/\"],\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/author\\\/certerabguser\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Critical Eventin WordPress Plugin Vulnerability Puts 10k+ Sites at Risk","description":"WordPress Eventin Plugin Vulnerability has put over 10,000 websites at serious risk. Patch now: 4.0.27. Checkout the recommendation actions.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/certera.com\/blog\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\/","og_locale":"en_US","og_type":"article","og_title":"CVE-2025-47539: Critical Eventin WordPress Plugin Vulnerability Puts 10,000+ Sites at Risk\u00a0","og_description":"WordPress Eventin Plugin Vulnerability has put over 10,000 websites at serious risk. Patch now: 4.0.27. Checkout the recommendation actions.","og_url":"https:\/\/certera.com\/blog\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\/","og_site_name":"EncryptedFence by Certera - Web &amp; Cyber Security Blog","article_publisher":"https:\/\/www.facebook.com\/certeraLLC\/","article_published_time":"2025-05-20T08:40:01+00:00","article_modified_time":"2025-05-20T08:40:02+00:00","og_image":[{"width":960,"height":620,"url":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/05\/eventin-plugin-vulnerability.webp","type":"image\/jpeg"}],"author":"Janki Mehta","twitter_card":"summary_large_image","twitter_creator":"@certera_llc","twitter_site":"@certera_llc","twitter_misc":{"Written by":"Janki Mehta","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/certera.com\/blog\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\/#article","isPartOf":{"@id":"https:\/\/certera.com\/blog\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\/"},"author":{"name":"Janki Mehta","@id":"https:\/\/certera.com\/blog\/#\/schema\/person\/e5a476aa90d9e02260ebfe4b0bf046b7"},"headline":"CVE-2025-47539: Critical Eventin WordPress Plugin Vulnerability Puts 10,000+ Sites at Risk\u00a0","datePublished":"2025-05-20T08:40:01+00:00","dateModified":"2025-05-20T08:40:02+00:00","mainEntityOfPage":{"@id":"https:\/\/certera.com\/blog\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\/"},"wordCount":706,"commentCount":0,"publisher":{"@id":"https:\/\/certera.com\/blog\/#organization"},"image":{"@id":"https:\/\/certera.com\/blog\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/05\/eventin-plugin-vulnerability.webp","articleSection":["Vulnerability"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/certera.com\/blog\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\/#respond"]}],"copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/certera.com\/blog\/#organization"}},{"@type":"WebPage","@id":"https:\/\/certera.com\/blog\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\/","url":"https:\/\/certera.com\/blog\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\/","name":"Critical Eventin WordPress Plugin Vulnerability Puts 10k+ Sites at Risk","isPartOf":{"@id":"https:\/\/certera.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/certera.com\/blog\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\/#primaryimage"},"image":{"@id":"https:\/\/certera.com\/blog\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/05\/eventin-plugin-vulnerability.webp","datePublished":"2025-05-20T08:40:01+00:00","dateModified":"2025-05-20T08:40:02+00:00","description":"WordPress Eventin Plugin Vulnerability has put over 10,000 websites at serious risk. Patch now: 4.0.27. Checkout the recommendation actions.","breadcrumb":{"@id":"https:\/\/certera.com\/blog\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/certera.com\/blog\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/certera.com\/blog\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\/#primaryimage","url":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/05\/eventin-plugin-vulnerability.webp","contentUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/05\/eventin-plugin-vulnerability.webp","width":960,"height":620,"caption":"Critical Eventin Plugin Vulnerability"},{"@type":"BreadcrumbList","@id":"https:\/\/certera.com\/blog\/critical-eventin-wordpress-plugin-vulnerability-puts-10000-sites-at-risk\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/certera.com\/blog\/"},{"@type":"ListItem","position":2,"name":"CVE-2025-47539: Critical Eventin WordPress Plugin Vulnerability Puts 10,000+ Sites at Risk\u00a0"}]},{"@type":"WebSite","@id":"https:\/\/certera.com\/blog\/#website","url":"https:\/\/certera.com\/blog\/","name":"EncryptedFence by Certera - Web & Cyber Security Blog","description":"","publisher":{"@id":"https:\/\/certera.com\/blog\/#organization"},"alternateName":"Certera's EncryptedFence Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/certera.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/certera.com\/blog\/#organization","name":"Certera","url":"https:\/\/certera.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/certera.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/08\/logo-encryptedfence.svg","contentUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/08\/logo-encryptedfence.svg","caption":"Certera"},"image":{"@id":"https:\/\/certera.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/certeraLLC\/","https:\/\/x.com\/certera_llc","https:\/\/www.linkedin.com\/company\/certera-llc\/"]},{"@type":"Person","@id":"https:\/\/certera.com\/blog\/#\/schema\/person\/e5a476aa90d9e02260ebfe4b0bf046b7","name":"Janki Mehta","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g","caption":"Janki Mehta"},"description":"Janki Mehta is a passionate Cyber-Security Enthusiast who keenly monitors the latest developments in the Web\/Cyber Security industry. She puts her knowledge into practice and helps web users by arming them with the necessary security measures to stay safe in the digital world.","sameAs":["https:\/\/certerassl.com\/"],"url":"https:\/\/certera.com\/blog\/author\/certerabguser\/"}]}},"_links":{"self":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts\/3569","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/comments?post=3569"}],"version-history":[{"count":2,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts\/3569\/revisions"}],"predecessor-version":[{"id":3571,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts\/3569\/revisions\/3571"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/media\/3574"}],"wp:attachment":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/media?parent=3569"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/categories?post=3569"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/tags?post=3569"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}