CVE-2026-9701Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of the password reset key in the `eventer_verification_code` user meta field when a user requests a password reset. The plaintext key stored in `wp_usermeta` can be used with the plugin's custom reset action to set a new password for any user. Combined with another vulnerability such as SQL Injection (CVE-2026-9700), this makes it possible for unauthenticated attackers to extract the plaintext reset key and take over any user account, including administrators. Note: The password reset function only works up to PHP version 7.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-289

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-07-08); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-08: 1Mentions · 2026-07-18: 1Patch / Workaround · 2026-07-08: 1Technical Details · 2026-07-08: 107-0807-18
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Orizon@OrizonCyber
    Disclosure

    🚨 CVE-2026-9701 — CVSS 9.8/10 ██████████ The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/cQFp6v5bOG

    Post summary

    The tweet announces a critical flaw (CVE‑2026‑9701) in the Eventer WordPress plugin, detailing an insecure password reset vulnerability with a CVSS of 9.8 and urging users to apply the patch immediately.

    1000072
    64 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    【緊急】CVE-2026-9701 WordPress用Eventerプラグイン(バージョン4.4.2まで)に深刻な脆弱性|即時対応が必要 https://www.cybernote.click/2026/07/15/cve-2026-9701-wordpresseventer442/ #IT #Security #cybersecurity

    Post summary

    The tweet announces a severe vulnerability (CVE-2026-9701) in the Eventer plugin for WordPress (up to v4.4.2) and urges immediate action, but it provides no technical details, PoC, or remediation information.

    0000094
    208 followersView on X

Explore more