# Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.25 - Unauthenticated Missing Authorization to Booking Status Update

- **ID:** WPSEC-2026-0449
- **Plugin:** Eventin – Events Calendar, Tickets, Registration, Booking & WooCommerce (`wp-event-solution`), https://wordpress.org/plugins/wp-event-solution/
- **Affected versions:** from 4.1.12 before 4.1.26
- **Fixed in:** 4.1.26 (Update to 4.1.26 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-863
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-event-solution
- **Fix released:** 2026-10-05
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0449/

## Description

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data in versions 4.1.12 up to, and including, 4.1.25 due to insufficient authorization on the booking status update action of the order update REST endpoint. A guest order access token, which is meant only for editing one's own order details, is accepted for this action. Starting in 4.1.19, a strict check in the permission callback can be bypassed by sending the 'action' parameter as a JSON boolean, because the endpoint compares it loosely. This makes it possible for unauthenticated attackers to mark their own unpaid orders as completed and receive valid tickets without paying.

## References

- https://wpsec.com/vuln/WPSEC-2026-0449/
- https://plugins.svn.wordpress.org/wp-event-solution/tags/4.1.26/
- https://wordpress.org/plugins/wp-event-solution/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0449/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
