Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.25 - Unauthenticated Sensitive Information Exposure via Event REST API

Medium 5.3 CWE-200Fixed in 4.1.26
ID
WPSEC-2026-0447
Plugin
Eventin – Events Calendar, Tickets, Registration, Booking & WooCommerce (wp-event-solution)
Affected
all versions before 4.1.26
Remediation
Update to 4.1.26 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-200
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
Attack surface
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.1.25. The legacy v1 single event REST route returns all raw event meta to anyone holding the public REST nonce, and the v2 event route does not remove every management-only field. This makes it possible for unauthenticated attackers to retrieve, for published events, CRM and automation webhook URLs and private virtual meeting join links, including Zoom, Google Meet and Custom URL links that are meant only for ticket holders.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0