Eventin

WordPress plugin · eventin · WordPress.org ↗
0
Critical
5
High
18
Known total
0
Unfixed
Running Eventin on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
HIGH
CVSS 7.2
Eventin < 4.1.21 - Contributor+ Speaker Account Deletion via IDOR
CVE.org
>=0, <4.1.21 v4.1.21 CVE-2026-13174 Aug 19, 2026
HIGH
CVSS 8.1
Eventin < 4.1.21 - Contributor+ Arbitrary Event Modification, Deletion and Ownership Takeover via IDOR
CVE.org
>=0, <4.1.21 v4.1.21 CVE-2026-13169 Aug 19, 2026
HIGH
CVSS 8.2
Eventin < 4.1.20 - Unauthenticated Account Creation via Waiting List Endpoint
CVE.org
>=0, <4.1.20 v4.1.20 CVE-2026-13171 Aug 12, 2026
HIGH
CVSS 7.2
Eventin < 4.1.20 - Editor+ Local File Inclusion via speaker_template Setting
CVE.org
>=0, <4.1.20 v4.1.20 CVE-2026-13170 Aug 10, 2026
HIGH
CVSS 7.5
Eventin < 4.1.16 - Unauthenticated Payment Bypass via Order Status Manipulation
CVE.org
>=0, <4.1.16 v4.1.16 CVE-2026-13178 Jul 30, 2026
MEDIUM
CVSS 5.3
Eventin < 4.1.24 - Unauthenticated Payment Bypass via Stripe and PayPal Cross-Order Transaction Replay
CVE.org
>=0, <4.1.24 v4.1.24 CVE-2026-84906 Sep 16, 2026
MEDIUM
CVSS 5.3
Eventin < 4.1.24 - Unauthenticated Ticket Price Rewrite via order_token
CVE.org
>=0, <4.1.24 v4.1.24 CVE-2026-77702 Sep 16, 2026
MEDIUM
CVSS 4.9
Eventin < 4.1.22 - Contributor+ Site Homepage Hijack and Event Taxonomy Manipulation via Missing Authorization
CVE.org
>=0, <4.1.22 v4.1.22 CVE-2026-84901 Sep 5, 2026
MEDIUM
CVSS 6.6
Eventin < 4.1.21 - Contributor+ LFI via Event Layout Meta
CVE.org
>=0, <4.1.21 v4.1.21 CVE-2026-84898 Sep 5, 2026
MEDIUM
CVSS 5.3
Eventin < 4.1.19 - Unauthenticated Order Completion Without Payment via order_token
CVE.org
>=0, <4.1.19 v4.1.19 CVE-2026-77694 Aug 26, 2026
MEDIUM
CVSS 5.3
Eventin < 4.1.22 - Unauthenticated Unpublished Content Disclosure
CVE.org
>=0, <4.1.22 v4.1.22 CVE-2026-13172 Aug 26, 2026
MEDIUM
CVSS 6.5
Eventin < 4.1.21 - Contributor+ Schedule Deletion and Modification via IDOR
CVE.org
>=0, <4.1.21 v4.1.21 CVE-2026-13175 Aug 19, 2026
MEDIUM
CVSS 4.3
Eventin < 4.1.20 - Contributor+ Order Information Disclosure via IDOR
CVE.org
>=4.1.9, <4.1.20 v4.1.20 CVE-2026-13177 Aug 12, 2026
MEDIUM
CVSS 6.5
Eventin < 4.1.20 - Contributor+ Customer PII Disclosure via REST API
CVE.org
>=0, <4.1.20 v4.1.20 CVE-2026-13168 Aug 12, 2026
LOW
CVSS 3.7
Eventin < 4.1.24 - Unauthenticated Order and Attendee Status Reset via Payment REST Endpoint
CVE.org
>=4.1.5, <4.1.24 v4.1.24 CVE-2026-84907 Sep 16, 2026
LOW
CVSS 2.7
Eventin < 4.1.24 - Contributor+ User Creation via Speaker Creation
CVE.org
>=0, <4.1.24 v4.1.24 CVE-2026-84905 Sep 16, 2026
LOW
CVSS 2.7
Eventin < 4.1.21 - Contributor+ Server-Side Request Forgery
CVE.org
>=0, <4.1.21 v4.1.21 CVE-2026-13176 Aug 21, 2026
LOW
CVSS 2.7
Eventin < 4.1.21 - Contributor+ User Role and Meta Modification via Speaker Creation
CVE.org
>=0, <4.1.21 v4.1.21 CVE-2026-13173 Aug 19, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.