CVE-2025-4796 is a privilege escalation vulnerability in the Eventin plugin for WordPress affecting all versions up to and including 4.0.34. The flaw is caused by missing authorization and identity validation in the Eventin\Speaker\Api\SpeakerController::update_item function, reported at SpeakerController.php line 419 in the provided context. The vulnerable endpoint allows a requester to update speaker-related user details, including email addresses, based on a user-controlled identifier without verifying that the requester is authorized to modify the targeted account. As a result, an authenticated attacker with contributor-level permissions or higher can change the email address of an arbitrary user, including an administrator. After replacing the victim's email with an attacker-controlled address, the attacker can use the normal WordPress password reset workflow to reset the victim's password and take over the account.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python exploit script (CVE-2025-4796.py) and a README describing an authenticated privilege escalation/account takeover issue in the Eventin WordPress plugin (<= 4.0.34). The exploit logs into WordPress with attacker-supplied Contributor+ credentials, then requests /wp-admin/post-new.php to extract a nonce token (x-wp-nonce) by regex-matching createnoncemiddleware("<alnum>") in the response. With cookies and nonce, it sends a PUT request to the Eventin REST API endpoint /wp-json/eventin/v2/speakers/{speaker_id} with JSON payload setting the speaker email to an attacker-controlled address. If the response is HTTP 200 and the returned JSON reflects the new email, it prints the updated object and the supplied credentials. The script disables TLS verification and suppresses urllib3 warnings. It does not automate the final password reset step, but the README explains that changing an admin email enables WordPress password reset to complete account takeover. Overall structure: helper functions for banner/printing, URL normalization, email validation, SSL warning disablement, WordPress login, nonce extraction, and the final email update request; main() prompts interactively for target URL, speaker_id, new email, username, and password.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.