Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.25 - Unauthenticated Sensitive Information Exposure via Event REST API
- ID
- WPSEC-2026-0447
- Plugin
- Eventin – Events Calendar, Tickets, Registration, Booking & WooCommerce (wp-event-solution)
- Affected
- all versions before 4.1.26
- Remediation
- Update to 4.1.26 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-200
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
- Attack surface
- Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce on WPSec AttackSurface
- Fix released
- Published
Description
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.1.25. The legacy v1 single event REST route returns all raw event meta to anyone holding the public REST nonce, and the v2 event route does not remove every management-only field. This makes it possible for unauthenticated attackers to retrieve, for published events, CRM and automation webhook URLs and private virtual meeting join links, including Zoom, Google Meet and Custom URL links that are meant only for ticket holders.
References
- https://wpsec.com/vuln/WPSEC-2026-0447/
- https://plugins.svn.wordpress.org/wp-event-solution/tags/4.1.26/
- https://wordpress.org/plugins/wp-event-solution/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS