Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.25 - Unauthenticated Payment Bypass via Mismatched Order Attendees
- ID
- WPSEC-2026-0446
- Plugin
- Eventin – Events Calendar, Tickets, Registration, Booking & WooCommerce (wp-event-solution)
- Affected
- from 4.0.9 before 4.1.26
- Remediation
- Update to 4.1.26 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-840
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
- Attack surface
- Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce on WPSec AttackSurface
- Fix released
- Published
Description
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to a business logic flaw in the order creation REST endpoint in versions 4.0.9 up to, and including, 4.1.25. The endpoint does not check that the submitted attendees match the purchased ticket lines: the order is charged for the ticket lines, while one ticket is issued per attendee, each for the ticket type that attendee names. This makes it possible for unauthenticated attackers to obtain more tickets than they paid for, or tickets of a paid ticket type while paying for a free or cheaper one.
References
- https://wpsec.com/vuln/WPSEC-2026-0446/
- https://plugins.svn.wordpress.org/wp-event-solution/tags/4.1.26/
- https://wordpress.org/plugins/wp-event-solution/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS