CVE-2025-47539

CRITICAL EXPLOITED NUCLEI

Eventin <= 4.0.26 - Privilege Escalation via Incorrect Privilege Assignment

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-47539 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 4 public exploits from researchers including cybersecplayground, Nxploited, snapdowgg. A Nuclei detection template is also available.

AI-analyzed exploit summary The repository contains detailed technical writeups for multiple CVEs, including CVE-2025-47539, with in-depth analysis, proof-of-concept examples, and mitigation recommendations. Each writeup provides specific technical details such as vulnerable endpoints, payload formats, and exploitation steps.

Description

Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a through <= 4.0.26.

Exploits (4)

github WRITEUP 7 stars
by cybersecplayground · poc
https://github.com/cybersecplayground/PoC-and-CVE-Reports/tree/main/2025/CVE-2025-47539.md

The repository contains detailed technical writeups for multiple CVEs, including CVE-2025-47539, with in-depth analysis, proof-of-concept examples, and mitigation recommendations. Each writeup provides specific technical details such as vulnerable endpoints, payload formats, and exploitation steps.

Classification
Writeup 95%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: Various (e.g., account_mgr.cgi, Ivanti Connect Secure, Zabbix, Check Point VPN, Bricks Builder)
No auth needed
Prerequisites: Access to vulnerable endpoints · Basic understanding of HTTP requests and payload crafting
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec WORKING POC 4 stars
by Nxploited · remote
https://github.com/Nxploited/CVE-2025-47539

This repository contains a functional Python exploit for CVE-2025-47539, an unauthenticated privilege escalation vulnerability in the WordPress Eventin plugin. The exploit crafts a malicious CSV file and uploads it via a vulnerable REST API endpoint to create an administrator account.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: WordPress Eventin Plugin <= 4.0.26
No auth needed
Prerequisites: Target running vulnerable WordPress Eventin plugin · Network access to the target
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by snapdowgg · remote
https://github.com/snapdowgg/CVE-2025-47539

This repository contains a functional exploit for CVE-2025-47539, targeting a WordPress plugin vulnerability via CSV import functionality to create an administrator account. The script supports both single and bulk target scanning.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: WordPress with vulnerable plugin (likely Eventin)
No auth needed
Prerequisites: WordPress site with vulnerable plugin installed · Access to the /wp-json/eventin/v2/speakers/import endpoint
devstral-2 · analyzed Feb 24, 2026 Full analysis →
github WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2025-47539

The repository contains functional exploit code for CVE-2025-47539, targeting a WordPress plugin (3DPrint Lite 1.9.1.4) with an arbitrary file upload vulnerability. The Python script demonstrates the vulnerability by uploading a shell to a vulnerable endpoint.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WordPress Plugin 3DPrint Lite 1.9.1.4
No auth needed
Prerequisites: Vulnerable WordPress plugin installed · Network access to the target
devstral-2 · analyzed Feb 27, 2026 Full analysis →

Nuclei Templates (1)

Eventin <= 4.0.26 - Privilege Escalation
CRITICALVERIFIEDby pdresearch
FOFA: body="/wp-content/plugins/eventin"

Scores

CVSS v3 9.8
EPSS 0.2790
EPSS Percentile 96.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2025-05-07
CWE
CWE-266
Status published
Products (2)
Arraytics/Eventin < 4.0.26
themewinter/eventin < 4.0.27
Published May 23, 2025
Tracked Since Feb 18, 2026