CVE-2026-4109Active Exploitation

LOWCVSS 4.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the get_item_permissions_check() function in all versions up to, and including, 4.1.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary order data including customer PII (name, email, phone) by iterating order IDs.

3.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 10 classified signals
  • 12 mentions across 11 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 10 signals
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Peaked 10d ago at 2 mentions (2026-04-14); latest day: 1
  • 12 total mentions across 11 days

Deep dive

Activity timeline12 mentions / 11d
01122Mentions · 2026-04-14: 2Mentions · 2026-06-06: 1Mentions · 2026-06-07: 1Mentions · 2026-06-08: 1Mentions · 2026-06-10: 1Mentions · 2026-06-14: 1Mentions · 2026-06-24: 1Mentions · 2026-06-30: 1Mentions · 2026-07-12: 1Mentions · 2026-09-02: 1Mentions · 2026-09-28: 1Active Exploitation · 2026-06-06: 1Active Exploitation · 2026-06-07: 1Active Exploitation · 2026-06-08: 1Active Exploitation · 2026-06-10: 1Active Exploitation · 2026-06-14: 1Active Exploitation · 2026-06-24: 1Active Exploitation · 2026-06-30: 1Active Exploitation · 2026-07-12: 1Active Exploitation · 2026-09-02: 1Active Exploitation · 2026-09-28: 1Technical Details · 2026-04-14: 204-1406-0606-0706-0806-1006-1406-2406-3007-1209-0209-28
Signal classification2 categories
Active Exploitation
1083.3%
General
216.7%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-142
General2
2026-06-061
Active Exploitation1
2026-06-071
Active Exploitation1
2026-06-081
Active Exploitation1
2026-06-101
Active Exploitation1
2026-06-141
Active Exploitation1
2026-06-241
Active Exploitation1
2026-06-301
Active Exploitation1
2026-07-121
Active Exploitation1
2026-09-021
Active Exploitation1
2026-09-281
Active Exploitation1
Full discourse12 posts
  • NEWSTECNICAS | Tecnología@newstecnicas
    Active Exploitation

    🚨 Alerta: Explotación activa de vulnerabilidades críticas en Microsoft Defender | CVE-2026-4109 | CVE-2026-45498 | https://www.newstecnicas.com/2026/06/alerta-explotacion-activa-de.html

    Post summary

    Alert reports active exploitation of Microsoft Defender CVE-2026-4109 and CVE-2026-45498, but does not provide PoC, exploit code, patches, or detailed technical information.

    0100045
    1.2K followersView on X
  • NEWSTECNICAS | Tecnología@newstecnicas
    Active Exploitation

    🚨 Alerta: Explotación activa de vulnerabilidades críticas en Microsoft Defender | CVE-2026-4109 | CVE-2026-45498 | https://www.newstecnicas.com/2026/06/alerta-explotacion-activa-de.html

    Post summary

    The tweet announces that CVE‑2026‑4109 and CVE‑2026‑45498 are being actively exploited in Microsoft Defender, but provides no technical details, PoC, or patch information.

    0100055
    1.2K followersView on X
  • NEWSTECNICAS | Tecnología@newstecnicas
    Active Exploitation

    🚨 Alerta: Explotación activa de #vulnerabilidades críticas en Microsoft Defender | CVE-2026-4109 | CVE-2026-45498 | https://www.newstecnicas.com/2026/06/alerta-explotacion-activa-de.html

    Post summary

    The tweet warns of active exploitation of critical Microsoft Defender vulnerabilities (CVE-2026-4109, CVE-2026-45498) and directs readers to a news source.

    0000032
    1.2K followersView on X
  • NEWSTECNICAS | Tecnología@newstecnicas
    Active Exploitation

    🚨 Alerta: Explotación activa de vulnerabilidades críticas en Microsoft Defender | CVE-2026-4109 | CVE-2026-45498 | https://www.newstecnicas.com/2026/06/alerta-explotacion-activa-de.html

    Post summary

    The text reports that critical vulnerabilities in Microsoft Defender (CVE-2026-4109 and CVE-2026-45498) are being actively exploited, but no additional technical or mitigation details are provided.

    0000031
    1.2K followersView on X
  • NEWSTECNICAS | Tecnología@newstecnicas
    Active Exploitation

    🚨 Alerta: Explotación activa de vulnerabilidades críticas en Microsoft Defender | CVE-2026-4109 | CVE-2026-45498 | https://www.newstecnicas.com/2026/06/alerta-explotacion-activa-de.html

    Post summary

    The snippet alerts readers to active exploitation of critical Microsoft Defender vulnerabilities CVE-2026-4109 and CVE-2026-45498, but does not provide PoC, exploit code, patch details, or technical specifics.

    0000045
    1.2K followersView on X
  • NEWSTECNICAS | Tecnología@newstecnicas
    Active Exploitation

    🚨 #Alerta: Explotación activa de #vulnerabilidades críticas en Microsoft #Defender | CVE-2026-4109 | CVE-2026-45498 | https://www.newstecnicas.com/2026/06/alerta-explotacion-activa-de.html

    Post summary

    The post alerts that CVE-2026-4109 and CVE-2026-45498 are actively exploited against Microsoft Defender, as reported by a news article.

    0000045
    1.2K followersView on X
  • NEWSTECNICAS | Tecnología, IA y Gaming.@newstecnicas
    Active Exploitation

    🚨 #Alerta: Explotación activa de #vulnerabilidades críticas en #MicrosoftDefender | CVE-2026-4109 | CVE-2026-45498 | https://www.newstecnicas.com/2026/06/alerta-explotacion-activa-de.html

    Post summary

    The post alerts to active exploitation of CVE-2026-4109 and CVE-2026-45498 in Microsoft Defender, though it offers no technical details or patch information.

    0000042
    1.2K followersView on X
  • NEWSTECNICAS | Tecnología, IA y Gaming.@newstecnicas
    Active Exploitation

    🚨 Alerta: Explotación activa de #vulnerabilidades críticas en Microsoft Defender | CVE-2026-4109 | CVE-2026-45498 | https://www.newstecnicas.com/2026/06/alerta-explotacion-activa-de.html

    Post summary

    The message alerts that Microsoft Defender is being actively exploited with CVE‑2026‑4109 and CVE‑2026‑45498, but does not provide exploit code, patches, or technical details.

    0000046
    1.2K followersView on X
  • NEWSTECNICAS | Tecnología, IA y Gaming.@newstecnicas
    Active Exploitation

    🚨 Alerta: #Explotación activa de #vulnerabilidades críticas en Microsoft #Defender | CVE-2026-4109 | CVE-2026-45498 | https://www.newstecnicas.com/2026/06/alerta-explotacion-activa-de.html

    Post summary

    An alert warns that Microsoft Defender is actively exploited through CVE-2026-4109 and CVE-2026-45498, but no patches or technical details are provided.

    0000048
    1.2K followersView on X
  • NEWSTECNICAS | Tecnología, IA y Gaming.@newstecnicas
    Active Exploitation

    🚨 #Alerta: Explotación activa de #vulnerabilidades críticas en #MicrosoftDefender | CVE-2026-4109 | CVE-2026-45498 | https://www.newstecnicas.com/2026/06/alerta-explotacion-activa-de.html

    Post summary

    The post alerts that CVE-2026-4109 and CVE-2026-45498 are being actively exploited against Microsoft Defender, with no PoC, exploit code, or mitigation details included.

    0000035
    1.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4109 Unauthorized Data Access in Eventin WordPress Plugin via Improper Capability Check https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4109

    Post summary

    The tweet offers a brief headline and a link to a vulnerability detail page, providing minimal technical context but lacking evidence of exploitation, patches, or a PoC.

    0000032
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4109 The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to unauthorized access of data due to a improper cap… https://www.cve.org/CVERecord?id=CVE-2026-4109

    Post summary

    The CVE describes a data‑access vulnerability in the Eventin WordPress plugin, but no exploit details, PoC, patch or active exploitation are provided.

    0000042
    57.2K followersView on X

Explore more