{
 "id": "WPSEC-2026-0447",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0447/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0447/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0447/index.md",
 "title": "Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.25 - Unauthenticated Sensitive Information Exposure via Event REST API",
 "description": "The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.1.25. The legacy v1 single event REST route returns all raw event meta to anyone holding the public REST nonce, and the v2 event route does not remove every management-only field. This makes it possible for unauthenticated attackers to retrieve, for published events, CRM and automation webhook URLs and private virtual meeting join links, including Zoom, Google Meet and Custom URL links that are meant only for ticket holders.",
 "plugin": {
  "slug": "wp-event-solution",
  "name": "Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce",
  "full_name": "Eventin – Events Calendar, Tickets, Registration, Booking & WooCommerce",
  "wordpress_org": "https://wordpress.org/plugins/wp-event-solution/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wp-event-solution/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wp-event-solution"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-200"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "4.1.26",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 4.1.26"
  ]
 },
 "introduced_in": null,
 "fixed_in": "4.1.26",
 "remediation": "Update to 4.1.26 or later.",
 "fix_released": "2026-10-05T09:35:45+00:00",
 "published": "2026-10-06T16:45:40+00:00",
 "updated": "2026-10-06T16:17:09.189801+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0447/",
  "https://plugins.svn.wordpress.org/wp-event-solution/tags/4.1.26/",
  "https://wordpress.org/plugins/wp-event-solution/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wp-event-solution",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-06"
 }
}