{
 "id": "WPSEC-2026-0446",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0446/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0446/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0446/index.md",
 "title": "Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.25 - Unauthenticated Payment Bypass via Mismatched Order Attendees",
 "description": "The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to a business logic flaw in the order creation REST endpoint in versions 4.0.9 up to, and including, 4.1.25. The endpoint does not check that the submitted attendees match the purchased ticket lines: the order is charged for the ticket lines, while one ticket is issued per attendee, each for the ticket type that attendee names. This makes it possible for unauthenticated attackers to obtain more tickets than they paid for, or tickets of a paid ticket type while paying for a free or cheaper one.",
 "plugin": {
  "slug": "wp-event-solution",
  "name": "Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce",
  "full_name": "Eventin – Events Calendar, Tickets, Registration, Booking & WooCommerce",
  "wordpress_org": "https://wordpress.org/plugins/wp-event-solution/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wp-event-solution/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wp-event-solution"
 },
 "type": "UNKNOWN",
 "cwe": [
  "CWE-840"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "4.0.9",
    "from_inclusive": true,
    "to": "4.1.26",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 4.0.9 before 4.1.26"
  ]
 },
 "introduced_in": "4.0.9",
 "fixed_in": "4.1.26",
 "remediation": "Update to 4.1.26 or later.",
 "fix_released": "2026-10-05T09:35:45+00:00",
 "published": "2026-10-06T16:45:40+00:00",
 "updated": "2026-10-06T16:17:09.189801+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0446/",
  "https://plugins.svn.wordpress.org/wp-event-solution/tags/4.1.26/",
  "https://wordpress.org/plugins/wp-event-solution/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wp-event-solution",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-06"
 }
}