Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesEventin

Eventin vulnerabilities

Eventin has 38 known vulnerabilities in this database. The most recent published record is dated 6 Oct 2026.

Known vulnerabilities
38
Active installs
10,000+
Latest version
4.1.25
Last updated
24 Sep 2026
Most recent
6 Oct 2026

No fixed version has been published yet, so consider disabling, removing or replacing the plugin until a safe release is available.

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Broken access control
CVE-2026-97300
Medium 6.5Up to 4.1.25No fixed version yet1 d ago
Broken access control
CVE-2026-103684
Medium 5.3Up to 4.1.25No fixed version yet2 d ago
Broken access control
CVE-2026-105073
Medium 5.3Up to 4.1.25No fixed version yet2 d ago
Security weakness
CVE-2026-84906
Medium 5.3Before 4.1.24Fixed in 4.1.2416 Sep 2026
Broken access control
CVE-2026-84905
Low 2.7Before 4.1.24Fixed in 4.1.2416 Sep 2026
Broken access control
CVE-2026-84907
Low 3.7Before 4.1.24Fixed in 4.1.2416 Sep 2026
Broken access control
CVE-2026-77702
Medium 5.3Before 4.1.24Fixed in 4.1.2416 Sep 2026
Remote code execution
CVE-2026-75983
High 7.5Up to 4.1.23Fixed in a later version (latest 4.1.25)15 Sep 2026
Cross-site scripting (XSS)
CVE-2026-15402
Medium 6.4Up to 4.1.23Fixed in a later version (latest 4.1.25)15 Sep 2026
Broken access control
CVE-2026-15398
Medium 4.3Up to 4.1.22Fixed in a later version (latest 4.1.25)9 Sep 2026
Broken access control
CVE-2026-11821
Medium 5.4Up to 4.1.17Fixed in a later version (latest 4.1.25)9 Sep 2026
File inclusion
CVE-2026-15406
High 7.5Up to 4.1.22Fixed in a later version (latest 4.1.25)9 Sep 2026
File inclusion
CVE-2026-15667
High 7.5Up to 4.1.22Fixed in a later version (latest 4.1.25)9 Sep 2026
Broken access control
CVE-2026-12956
Medium 5.3Up to 4.1.22Fixed in a later version (latest 4.1.25)9 Sep 2026
Path traversal
CVE-2026-84898
Medium 6.6Before 4.1.21Fixed in 4.1.215 Sep 2026
Broken access control
CVE-2026-84901
Medium 4.9Before 4.1.22Fixed in 4.1.225 Sep 2026
Broken access control
CVE-2026-77694
Medium 5.3Before 4.1.19Fixed in 4.1.1926 Aug 2026
Broken access control
CVE-2026-13172
Medium 5.3Before 4.1.22Fixed in 4.1.2226 Aug 2026
Server-side request forgery (SSRF)
CVE-2026-13176
Low 2.7Before 4.1.21Fixed in 4.1.2121 Aug 2026
Broken access control
CVE-2026-13174
High 7.2Before 4.1.21Fixed in 4.1.2119 Aug 2026
Broken access control
CVE-2026-13175
Medium 6.5Before 4.1.21Fixed in 4.1.2119 Aug 2026
Broken access control
CVE-2026-13169
High 8.1Before 4.1.21Fixed in 4.1.2119 Aug 2026
Broken access control
CVE-2026-13173
Low 2.7Before 4.1.21Fixed in 4.1.2119 Aug 2026
Broken access control
CVE-2026-13177
Medium 4.3Before 4.1.20Fixed in 4.1.2012 Aug 2026
Broken access control
CVE-2026-13171
High 8.2Before 4.1.20Fixed in 4.1.2012 Aug 2026
Sensitive data exposure
CVE-2026-13168
Medium 6.5Before 4.1.20Fixed in 4.1.2012 Aug 2026
Path traversal
CVE-2026-13170
High 7.2Before 4.1.20Fixed in 4.1.2010 Aug 2026
Broken access control
CVE-2026-13178
High 7.5Before 4.1.16Fixed in 4.1.1630 Jul 2026
Cross-site scripting (XSS)
CVE-2026-12924
Medium 6.4Up to 4.1.15Fixed in a later version (latest 4.1.25)10 Jul 2026
Broken access control
CVE-2025-14657
High 7.2Up to 4.0.51Fixed in a later version (latest 4.1.25)9 Jan 2026
Server-side request forgery (SSRF)
CVE-2025-7813
High 7.2Up to 4.0.37Fixed in a later version (latest 4.1.25)23 Aug 2025
Privilege escalation
CVE-2025-4796
High 8.8Before 4.0.35Fixed in 4.0.358 Aug 2025
Arbitrary file read
CVE-2025-3419
High 7.5Before 4.0.27Fixed in 4.0.278 May 2025
Broken access control
CVE-2025-1766
Medium 5.3Before 4.0.25Fixed in 4.0.2520 Mar 2025
File inclusion
CVE-2025-1770
High 8.8Before 4.0.25Fixed in 4.0.2520 Mar 2025
File inclusion
CVE-2024-7149
High 8.8Before 4.0.9Fixed in 4.0.927 Sep 2024
Broken access control
CVE-2024-6033
Medium 4.3Before 4.0.5Fixed in 4.0.517 Jul 2024
Broken access control
CVE-2024-1122
Medium 5.3Before 3.3.51Fixed in 3.3.519 Feb 2024
Read the published descriptions
CVE-2026-97300, 6 Oct 2026
Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions. CVE record
CVE-2026-103684, 5 Oct 2026
Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Solution: from n/a through 4.1.25. CVE record
CVE-2026-105073, 5 Oct 2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Arraytics WP Event Solution wp-event-solution allows Retrieve Embedded Sensitive Data.This issue affects WP Event Solution: from n/a through 4.1.25. CVE record
CVE-2026-84906, 16 Sep 2026
The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its amount, currency, or which order it belongs to, allowing unauthenticated visitors to mark unpaid orders of any value as paid by replaying the transaction of a single genuine low-value payment. CVE record
CVE-2026-84905, 16 Sep 2026
The Eventin WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speaker, allowing users with contributor-level access and above to create new WordPress user accounts that carry capabilities beyond their own, including publishing content and uploading files, and, by supplying an email address they control, to obtain a working login to the created account. CVE record
CVE-2026-84907, 16 Sep 2026
The Eventin WordPress plugin before 4.1.24 does not properly authorise order finalisation when its offline (local) payment method is enabled, relying on a nonce that is exposed to unauthenticated visitors and never checking that the caller owns the order, allowing unauthenticated attackers to reset any existing order and its attendees to a pending state and thereby invalidate paid tickets. CVE record
CVE-2026-77702, 16 Sep 2026
The Eventin WordPress plugin before 4.1.24 does not prevent the token issued to a guest at checkout from being used to change that order's tickets afterwards, allowing unauthenticated users to replace a paid ticket with a free one and complete the order at no charge. CVE record
CVE-2026-75983, 15 Sep 2026
The Eventin - Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` function being registered as a callback on WordPress core's `map_meta_cap` filter and unconditionally returning the always-true `'exist'` primitive for every capability check whenever the evaluated user ID is 1, without scoping this behavior to plugin-specific capabilities. This makes it possible for authenticated attackers whose account is user ID 1, even subscribers, to pass every WordPress capability check, including `manage_options`, `edit_plugins`, `edit_themes`, `promote_users`, and `update_core`, thereby elevating their privileges to administrator-equivalent power and achieving full site takeover, including remote code execution via the plugin and theme editors. Exploitation is only impactful when user ID 1 has been deliberately demoted to a lower-privilege role as a common administrator-account hardening practice; on default installations where user ID 1 retains the administrator role, no incremental privilege gain occurs. CVE record
CVE-2026-15402, 15 Sep 2026
The Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter in all versions up to, and including, 4.1.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-15398, 9 Sep 2026
The Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.22. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to bypass payment for paid events, fraudulently mark orders as completed, deplete ticket inventory, and trigger confirmation emails for tickets never purchased. This is exploitable by unauthenticated attackers because the wp_rest nonce is publicly emitted on every frontend page, and the order creation endpoint mints and returns an order_access_token to any caller possessing that nonce - giving unauthenticated users all credentials required to reach the privileged update_booking_status branch. CVE record
CVE-2026-11821, 9 Sep 2026
The Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to view, create, update, clone, and delete notification flow event automation workflows that should be restricted to administrators. CVE record
CVE-2026-15406, 9 Sep 2026
The Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with custom-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. CVE record
CVE-2026-15667, 9 Sep 2026
The Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The etn_manage_event capability is assigned to Contributors by default, meaning any Contributor-level user can set the malicious event_layout value via the REST API without any additional configuration. CVE record
CVE-2026-12956, 9 Sep 2026
The WP Event Solution (Eventin) plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 4.1.22 via the create_item() handler for the /wp-json/eventin/v2/orders REST endpoint. The endpoint's create_item_permissions_check() function only verifies a wp_rest nonce (which is leaked to every visitor through the etn-public script's localized_data_obj on every frontend page) and accepts a user-supplied 'status' value in prepare_item_for_database() with no whitelist validation. This makes it possible for unauthenticated attackers to create etn-order posts with status='completed' that are counted as sold by etn_get_sold_tickets_by_event(); because the auto-cleanup wp_schedule_single_event() in create_item() only fires for status='pending' orders, the forged completed orders persist indefinitely and exhaust ticket inventory. CVE record
CVE-2026-84898, 5 Sep 2026
The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with contributor-level access and above to include and execute arbitrary local PHP files. CVE record
CVE-2026-84901, 5 Sep 2026
The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy terms they should not be able to manage. CVE record
CVE-2026-77694, 26 Aug 2026
The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed to authorise on an order, allowing unauthenticated users to mark their own unpaid order as completed and be issued a valid paid ticket with no payment taken. CVE record
CVE-2026-13172, 26 Aug 2026
The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing unauthenticated users to retrieve draft, pending and private posts belonging to other users, along with the passwords and contents of password-protected ones. CVE record
CVE-2026-13176, 21 Aug 2026
The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify event ownership, allowing users with contributor-level access and above to trigger blind server-side requests to arbitrary hosts. CVE record
CVE-2026-13174, 19 Aug 2026
The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts. CVE record
CVE-2026-13175, 19 Aug 2026
The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with contributor-level access and above to alter or delete schedule entries created by other users. CVE record
CVE-2026-13169, 19 Aug 2026
The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned to a different author, allowing users with contributor-level access and above to alter, delete, or take over events created by other users including administrators. CVE record
CVE-2026-13173, 19 Aug 2026
The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users with contributor-level access and above to modify other users' roles and metadata. CVE record
CVE-2026-13177, 12 Aug 2026
The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing users with contributor-level access and above to read other customers' order data including personal information by iterating order identifiers. CVE record
CVE-2026-13171, 12 Aug 2026
The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticated users to create WordPress user accounts for arbitrary email addresses and inject order records. CVE record
CVE-2026-13168, 12 Aug 2026
The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users with contributor-level access and above to read other customers' personal data such as names and email addresses. CVE record
CVE-2026-13170, 10 Aug 2026
The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files. CVE record
CVE-2026-13178, 30 Jul 2026
The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment. CVE record
CVE-2026-12924, 10 Jul 2026
The Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter in all versions up to, and including, 4.1.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-14657, 9 Jan 2026
The Eventin - Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'post_settings' function in all versions up to, and including, 4.0.51. This makes it possible for unauthenticated attackers to modify plugin settings. Furthermore, due to insufficient input sanitization and output escaping on the 'etn_primary_color' setting, this enables unauthenticated attackers to inject arbitrary web scripts that will execute whenever a user accesses a page where Eventin styles are loaded. CVE record
CVE-2025-7813, 23 Aug 2025
The Events Calendar, Event Booking, Registrations and Event Tickets - Eventin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.37 via the proxy_image function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. CVE record
CVE-2025-4796, 8 Aug 2025
The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due to the plugin not properly validating a user's identity or capability prior to updating their details like email in the 'Eventin\Speaker\Api\SpeakerController::update_item' function. This makes it possible for unauthenticated attackers with contributor-level and above permissions to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account. CVE record
CVE-2025-3419, 8 May 2025
The Event Manager, Events Calendar, Tickets, Registrations - Eventin plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 4.0.26 via the proxy_image() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. CVE-2025-47445 is a duplicate of this vulnerability. CVE record
CVE-2025-1766, 20 Mar 2025
The Event Manager, Events Calendar, Tickets, Registrations - Eventin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'payment_complete' function in all versions up to, and including, 4.0.24. This makes it possible for unauthenticated attackers to update the status of ticket payments to 'completed', possibly resulting in financial loss. CVE record
CVE-2025-1770, 20 Mar 2025
The Event Manager, Events Calendar, Tickets, Registrations - Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.24 via the 'style' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. CVE record
CVE-2024-7149, 27 Sep 2024
The Event Manager, Events Calendar, Tickets, Registrations - Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.8 via multiple style parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. CVE record
CVE-2024-6033, 17 Jul 2024
The Event Manager, Events Calendar, Tickets, Registrations - Eventin plugin for WordPress is vulnerable to unauthorized data importation due to a missing capability check on the 'import_file' function in all versions up to, and including, 4.0.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to import events, speakers, schedules and attendee data. CVE record
CVE-2024-1122, 9 Feb 2024
The Event Manager, Events Calendar, Events Tickets for WooCommerce - Eventin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_data() function in all versions up to, and including, 3.3.50. This makes it possible for unauthenticated attackers to export event data. CVE record

What to do if you run Eventin

If you run Eventin, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Eventin vulnerabilities

Free. We email you when a new vulnerability is published for Eventin, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support