Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.25 - Unauthenticated Sensitive Information Exposure via Event Structured Data

Low 3.7 CWE-200Fixed in 4.1.26
ID
WPSEC-2026-0448
Plugin
Eventin – Events Calendar, Tickets, Registration, Booking & WooCommerce (wp-event-solution)
Affected
from 4.1.24 before 4.1.26
Remediation
Update to 4.1.26 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-200
Usage
Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-06
Attack surface
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 4.1.24 up to, and including, 4.1.25 because the event JSON-LD structured data uses the event's virtual meeting join link as its location URL. When schema mark-up is enabled, this makes it possible for unauthenticated attackers to read Zoom, Google Meet or other join links for online and hybrid events from the public event page source without buying a ticket.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0