Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.25 - Unauthenticated Missing Authorization to Booking Status Update
- ID
- WPSEC-2026-0449
- Plugin
- Eventin – Events Calendar, Tickets, Registration, Booking & WooCommerce (wp-event-solution)
- Affected
- from 4.1.12 before 4.1.26
- Remediation
- Update to 4.1.26 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-863
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
- Attack surface
- Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce on WPSec AttackSurface
- Fix released
- Published
Description
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data in versions 4.1.12 up to, and including, 4.1.25 due to insufficient authorization on the booking status update action of the order update REST endpoint. A guest order access token, which is meant only for editing one's own order details, is accepted for this action. Starting in 4.1.19, a strict check in the permission callback can be bypassed by sending the 'action' parameter as a JSON boolean, because the endpoint compares it loosely. This makes it possible for unauthenticated attackers to mark their own unpaid orders as completed and receive valid tickets without paying.
References
- https://wpsec.com/vuln/WPSEC-2026-0449/
- https://plugins.svn.wordpress.org/wp-event-solution/tags/4.1.26/
- https://wordpress.org/plugins/wp-event-solution/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS