# Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.25 - Unauthenticated Sensitive Information Exposure via Event REST API

- **ID:** WPSEC-2026-0447
- **Plugin:** Eventin – Events Calendar, Tickets, Registration, Booking & WooCommerce (`wp-event-solution`), https://wordpress.org/plugins/wp-event-solution/
- **Affected versions:** all versions before 4.1.26
- **Fixed in:** 4.1.26 (Update to 4.1.26 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-200
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-event-solution
- **Fix released:** 2026-10-05
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0447/

## Description

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.1.25. The legacy v1 single event REST route returns all raw event meta to anyone holding the public REST nonce, and the v2 event route does not remove every management-only field. This makes it possible for unauthenticated attackers to retrieve, for published events, CRM and automation webhook URLs and private virtual meeting join links, including Zoom, Google Meet and Custom URL links that are meant only for ticket holders.

## References

- https://wpsec.com/vuln/WPSEC-2026-0447/
- https://plugins.svn.wordpress.org/wp-event-solution/tags/4.1.26/
- https://wordpress.org/plugins/wp-event-solution/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0447/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
