Vulnerabilities / Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce / WPSEC-2026-0448
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.25 - Unauthenticated Sensitive Information Exposure via Event Structured Data
Low 3.7
CWE-200Fixed in 4.1.26
- ID
- WPSEC-2026-0448
- Plugin
- Eventin – Events Calendar, Tickets, Registration, Booking & WooCommerce (wp-event-solution)
- Affected
- from 4.1.24 before 4.1.26
- Remediation
- Update to 4.1.26 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-200
- Usage
- Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-06
- Attack surface
- Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce on WPSec AttackSurface
- Fix released
- Published
Description
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 4.1.24 up to, and including, 4.1.25 because the event JSON-LD structured data uses the event's virtual meeting join link as its location URL. When schema mark-up is enabled, this makes it possible for unauthenticated attackers to read Zoom, Google Meet or other join links for online and hybrid events from the public event page source without buying a ticket.
References
- https://wpsec.com/vuln/WPSEC-2026-0448/
- https://plugins.svn.wordpress.org/wp-event-solution/tags/4.1.26/
- https://wordpress.org/plugins/wp-event-solution/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS