# Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.25 - Unauthenticated Sensitive Information Exposure via Event Structured Data

- **ID:** WPSEC-2026-0448
- **Plugin:** Eventin – Events Calendar, Tickets, Registration, Booking & WooCommerce (`wp-event-solution`), https://wordpress.org/plugins/wp-event-solution/
- **Affected versions:** from 4.1.24 before 4.1.26
- **Fixed in:** 4.1.26 (Update to 4.1.26 or later.)
- **Severity:** Low 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-200
- **Usage among sites WPSec scans:** plugin Medium, affected versions Low (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-event-solution
- **Fix released:** 2026-10-05
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0448/

## Description

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 4.1.24 up to, and including, 4.1.25 because the event JSON-LD structured data uses the event's virtual meeting join link as its location URL. When schema mark-up is enabled, this makes it possible for unauthenticated attackers to read Zoom, Google Meet or other join links for online and hybrid events from the public event page source without buying a ticket.

## References

- https://wpsec.com/vuln/WPSEC-2026-0448/
- https://plugins.svn.wordpress.org/wp-event-solution/tags/4.1.26/
- https://wordpress.org/plugins/wp-event-solution/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0448/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
