CVE-2026-40776
HighPublished
WordPress Eventin plugin <= 4.1.8 - Broken Access Control vulnerability
- Published
- Jun 15, 2026
- Updated
- Jun 16, 2026
- Assigning CNA
- Patchstack
- Evidence observed
- Aug 28, 2026
Primary CVSS
7.5/ 10High
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N0.4%
Low · next 30 days
- Percentile
- 35.2%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions.
Sources
1CVE-2026-40776 — Broken Access Control + IDOR in WordPress Eventin (wp-event-solution) <= 4.1.8
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.