CVE-2026-77694 PUBLISHED

Eventin < 4.1.19 - Unauthenticated Order Completion Without Payment via order_token

Assigner: WPScan
Reserved: 21.08.2026 Published: 26.08.2026 Updated: 26.08.2026

The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed to authorise on an order, allowing unauthenticated users to mark their own unpaid order as completed and be issued a valid paid ticket with no payment taken.

Product Status

Vendor Unknown
Product Eventin
Versions Default: unaffected
  • affected from 0 to 4.1.19 (excl.)

Credits

  • Nir Yehoshua finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE