Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.25 - Unauthenticated Payment Bypass via Mismatched Order Attendees

Medium 5.3 CWE-840Fixed in 4.1.26
ID
WPSEC-2026-0446
Plugin
Eventin – Events Calendar, Tickets, Registration, Booking & WooCommerce (wp-event-solution)
Affected
from 4.0.9 before 4.1.26
Remediation
Update to 4.1.26 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-840
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
Attack surface
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to a business logic flaw in the order creation REST endpoint in versions 4.0.9 up to, and including, 4.1.25. The endpoint does not check that the submitted attendees match the purchased ticket lines: the order is charged for the ticket lines, while one ticket is issued per attendee, each for the ticket type that attendee names. This makes it possible for unauthenticated attackers to obtain more tickets than they paid for, or tickets of a paid ticket type while paying for a free or cheaper one.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0