Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.25 - Unauthenticated Missing Authorization to Booking Status Update

Medium 5.3 CWE-863Fixed in 4.1.26
ID
WPSEC-2026-0449
Plugin
Eventin – Events Calendar, Tickets, Registration, Booking & WooCommerce (wp-event-solution)
Affected
from 4.1.12 before 4.1.26
Remediation
Update to 4.1.26 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-863
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
Attack surface
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data in versions 4.1.12 up to, and including, 4.1.25 due to insufficient authorization on the booking status update action of the order update REST endpoint. A guest order access token, which is meant only for editing one's own order details, is accepted for this action. Starting in 4.1.19, a strict check in the permission callback can be bypassed by sending the 'action' parameter as a JSON boolean, because the endpoint compares it loosely. This makes it possible for unauthenticated attackers to mark their own unpaid orders as completed and receive valid tickets without paying.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0