Target Industry
Indiscriminate, opportunistic targeting.
Overview
A new critical vulnerability has been identified which is affecting over 10,000 WordPress sites using the Eventin plugin. It has been tracked as CVE-2025-47539 with a base score of 9.8. The vulnerability allows unauthenticated threat actors to escalate their privileges to administrator via a vulnerable REST API endpoint, potentially leading to complete site compromise.
Impact
The impact of the CVE-2025-47539 vulnerability is severe. Threat actors can gain administrator privileges, allowing them to take full control of the affected WordPress site. This can lead to a data breach, with sensitive information being accessed, modified, or deleted.
Additionally, threat actors can inject malicious code or malware, potentially spreading it to site visitors. The site could be defaced or taken offline, disrupting services and damaging its reputation. Furthermore, malicious activities can result in blacklisting by search engines, negatively affecting the site’s search engine ranking.
Exploitation
The CVE-2025-47539 vulnerability is exploited through a flaw in the Eventin plugin’s REST API endpoint /wp-json/eventin/v2/speakers/import. The endpoint has a flawed permission_callback function that always returns true, allowing any user to access it without proper authentication.
A threat actor can exploit this by sending a specially crafted CSV file to the endpoint. This file contains data that, when processed, creates a new user account with administrator privileges. With these privileges, the threat actor can take full control of the WordPress site, leading to potential data breaches, malware injection, site defacement, and other malicious activities.
Affected Products
The affected product is the Eventin plugin for WordPress, developed by Themewinter. The vulnerability impacts versions up to and including 4.0.26
Containment, Mitigations & Remediations
It is highly recommended to update the Eventin plugin to the latest version. If updating isn’t possible immediately, temporarily disabling the plugin is recommended to prevent potential exploitation
Threat Landscape
The risk posed by CVE-2025-47539 to organisations is severe. It is reported that more than 10,000 websites using this plugin are at risk of being fully compromised. This can lead to potential data breaches, malware injection, site defacement, and other malicious activities.
Further Information













