{
 "id": "WPSEC-2026-0449",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0449/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0449/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0449/index.md",
 "title": "Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.25 - Unauthenticated Missing Authorization to Booking Status Update",
 "description": "The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data in versions 4.1.12 up to, and including, 4.1.25 due to insufficient authorization on the booking status update action of the order update REST endpoint. A guest order access token, which is meant only for editing one's own order details, is accepted for this action. Starting in 4.1.19, a strict check in the permission callback can be bypassed by sending the 'action' parameter as a JSON boolean, because the endpoint compares it loosely. This makes it possible for unauthenticated attackers to mark their own unpaid orders as completed and receive valid tickets without paying.",
 "plugin": {
  "slug": "wp-event-solution",
  "name": "Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce",
  "full_name": "Eventin – Events Calendar, Tickets, Registration, Booking & WooCommerce",
  "wordpress_org": "https://wordpress.org/plugins/wp-event-solution/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wp-event-solution/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wp-event-solution"
 },
 "type": "NO AUTHORISATION",
 "cwe": [
  "CWE-863"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "4.1.12",
    "from_inclusive": true,
    "to": "4.1.26",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 4.1.12 before 4.1.26"
  ]
 },
 "introduced_in": "4.1.12",
 "fixed_in": "4.1.26",
 "remediation": "Update to 4.1.26 or later.",
 "fix_released": "2026-10-05T09:35:45+00:00",
 "published": "2026-10-06T16:45:40+00:00",
 "updated": "2026-10-06T16:17:09.189801+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0449/",
  "https://plugins.svn.wordpress.org/wp-event-solution/tags/4.1.26/",
  "https://wordpress.org/plugins/wp-event-solution/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wp-event-solution",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-06"
 }
}