HomeWordPress vulnerabilitiesEventin
Eventin vulnerabilities
Eventin has 38 known vulnerabilities in this database. The most recent published record is dated 6 Oct 2026.
- Known vulnerabilities
- 38
- Active installs
- 10,000+
- Latest version
- 4.1.25
- Last updated
- 24 Sep 2026
- Most recent
- 6 Oct 2026
No fixed version has been published yet, so consider disabling, removing or replacing the plugin until a safe release is available.
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Broken access control CVE-2026-97300 | Medium 6.5 | Up to 4.1.25 | No fixed version yet | 1 d ago |
| Broken access control CVE-2026-103684 | Medium 5.3 | Up to 4.1.25 | No fixed version yet | 2 d ago |
| Broken access control CVE-2026-105073 | Medium 5.3 | Up to 4.1.25 | No fixed version yet | 2 d ago |
| Security weakness CVE-2026-84906 | Medium 5.3 | Before 4.1.24 | Fixed in 4.1.24 | 16 Sep 2026 |
| Broken access control CVE-2026-84905 | Low 2.7 | Before 4.1.24 | Fixed in 4.1.24 | 16 Sep 2026 |
| Broken access control CVE-2026-84907 | Low 3.7 | Before 4.1.24 | Fixed in 4.1.24 | 16 Sep 2026 |
| Broken access control CVE-2026-77702 | Medium 5.3 | Before 4.1.24 | Fixed in 4.1.24 | 16 Sep 2026 |
| Remote code execution CVE-2026-75983 | High 7.5 | Up to 4.1.23 | Fixed in a later version (latest 4.1.25) | 15 Sep 2026 |
| Cross-site scripting (XSS) CVE-2026-15402 | Medium 6.4 | Up to 4.1.23 | Fixed in a later version (latest 4.1.25) | 15 Sep 2026 |
| Broken access control CVE-2026-15398 | Medium 4.3 | Up to 4.1.22 | Fixed in a later version (latest 4.1.25) | 9 Sep 2026 |
| Broken access control CVE-2026-11821 | Medium 5.4 | Up to 4.1.17 | Fixed in a later version (latest 4.1.25) | 9 Sep 2026 |
| File inclusion CVE-2026-15406 | High 7.5 | Up to 4.1.22 | Fixed in a later version (latest 4.1.25) | 9 Sep 2026 |
| File inclusion CVE-2026-15667 | High 7.5 | Up to 4.1.22 | Fixed in a later version (latest 4.1.25) | 9 Sep 2026 |
| Broken access control CVE-2026-12956 | Medium 5.3 | Up to 4.1.22 | Fixed in a later version (latest 4.1.25) | 9 Sep 2026 |
| Path traversal CVE-2026-84898 | Medium 6.6 | Before 4.1.21 | Fixed in 4.1.21 | 5 Sep 2026 |
| Broken access control CVE-2026-84901 | Medium 4.9 | Before 4.1.22 | Fixed in 4.1.22 | 5 Sep 2026 |
| Broken access control CVE-2026-77694 | Medium 5.3 | Before 4.1.19 | Fixed in 4.1.19 | 26 Aug 2026 |
| Broken access control CVE-2026-13172 | Medium 5.3 | Before 4.1.22 | Fixed in 4.1.22 | 26 Aug 2026 |
| Server-side request forgery (SSRF) CVE-2026-13176 | Low 2.7 | Before 4.1.21 | Fixed in 4.1.21 | 21 Aug 2026 |
| Broken access control CVE-2026-13174 | High 7.2 | Before 4.1.21 | Fixed in 4.1.21 | 19 Aug 2026 |
| Broken access control CVE-2026-13175 | Medium 6.5 | Before 4.1.21 | Fixed in 4.1.21 | 19 Aug 2026 |
| Broken access control CVE-2026-13169 | High 8.1 | Before 4.1.21 | Fixed in 4.1.21 | 19 Aug 2026 |
| Broken access control CVE-2026-13173 | Low 2.7 | Before 4.1.21 | Fixed in 4.1.21 | 19 Aug 2026 |
| Broken access control CVE-2026-13177 | Medium 4.3 | Before 4.1.20 | Fixed in 4.1.20 | 12 Aug 2026 |
| Broken access control CVE-2026-13171 | High 8.2 | Before 4.1.20 | Fixed in 4.1.20 | 12 Aug 2026 |
| Sensitive data exposure CVE-2026-13168 | Medium 6.5 | Before 4.1.20 | Fixed in 4.1.20 | 12 Aug 2026 |
| Path traversal CVE-2026-13170 | High 7.2 | Before 4.1.20 | Fixed in 4.1.20 | 10 Aug 2026 |
| Broken access control CVE-2026-13178 | High 7.5 | Before 4.1.16 | Fixed in 4.1.16 | 30 Jul 2026 |
| Cross-site scripting (XSS) CVE-2026-12924 | Medium 6.4 | Up to 4.1.15 | Fixed in a later version (latest 4.1.25) | 10 Jul 2026 |
| Broken access control CVE-2025-14657 | High 7.2 | Up to 4.0.51 | Fixed in a later version (latest 4.1.25) | 9 Jan 2026 |
| Server-side request forgery (SSRF) CVE-2025-7813 | High 7.2 | Up to 4.0.37 | Fixed in a later version (latest 4.1.25) | 23 Aug 2025 |
| Privilege escalation CVE-2025-4796 | High 8.8 | Before 4.0.35 | Fixed in 4.0.35 | 8 Aug 2025 |
| Arbitrary file read CVE-2025-3419 | High 7.5 | Before 4.0.27 | Fixed in 4.0.27 | 8 May 2025 |
| Broken access control CVE-2025-1766 | Medium 5.3 | Before 4.0.25 | Fixed in 4.0.25 | 20 Mar 2025 |
| File inclusion CVE-2025-1770 | High 8.8 | Before 4.0.25 | Fixed in 4.0.25 | 20 Mar 2025 |
| File inclusion CVE-2024-7149 | High 8.8 | Before 4.0.9 | Fixed in 4.0.9 | 27 Sep 2024 |
| Broken access control CVE-2024-6033 | Medium 4.3 | Before 4.0.5 | Fixed in 4.0.5 | 17 Jul 2024 |
| Broken access control CVE-2024-1122 | Medium 5.3 | Before 3.3.51 | Fixed in 3.3.51 | 9 Feb 2024 |
Read the published descriptions
- CVE-2026-97300, 6 Oct 2026
- Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions. CVE record
- CVE-2026-103684, 5 Oct 2026
- Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Solution: from n/a through 4.1.25. CVE record
- CVE-2026-105073, 5 Oct 2026
- Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Arraytics WP Event Solution wp-event-solution allows Retrieve Embedded Sensitive Data.This issue affects WP Event Solution: from n/a through 4.1.25. CVE record
- CVE-2026-84906, 16 Sep 2026
- The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its amount, currency, or which order it belongs to, allowing unauthenticated visitors to mark unpaid orders of any value as paid by replaying the transaction of a single genuine low-value payment. CVE record
- CVE-2026-84905, 16 Sep 2026
- The Eventin WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speaker, allowing users with contributor-level access and above to create new WordPress user accounts that carry capabilities beyond their own, including publishing content and uploading files, and, by supplying an email address they control, to obtain a working login to the created account. CVE record
- CVE-2026-84907, 16 Sep 2026
- The Eventin WordPress plugin before 4.1.24 does not properly authorise order finalisation when its offline (local) payment method is enabled, relying on a nonce that is exposed to unauthenticated visitors and never checking that the caller owns the order, allowing unauthenticated attackers to reset any existing order and its attendees to a pending state and thereby invalidate paid tickets. CVE record
- CVE-2026-77702, 16 Sep 2026
- The Eventin WordPress plugin before 4.1.24 does not prevent the token issued to a guest at checkout from being used to change that order's tickets afterwards, allowing unauthenticated users to replace a paid ticket with a free one and complete the order at no charge. CVE record
- CVE-2026-75983, 15 Sep 2026
- The Eventin - Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` function being registered as a callback on WordPress core's `map_meta_cap` filter and unconditionally returning the always-true `'exist'` primitive for every capability check whenever the evaluated user ID is 1, without scoping this behavior to plugin-specific capabilities. This makes it possible for authenticated attackers whose account is user ID 1, even subscribers, to pass every WordPress capability check, including `manage_options`, `edit_plugins`, `edit_themes`, `promote_users`, and `update_core`, thereby elevating their privileges to administrator-equivalent power and achieving full site takeover, including remote code execution via the plugin and theme editors. Exploitation is only impactful when user ID 1 has been deliberately demoted to a lower-privilege role as a common administrator-account hardening practice; on default installations where user ID 1 retains the administrator role, no incremental privilege gain occurs. CVE record
- CVE-2026-15402, 15 Sep 2026
- The Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter in all versions up to, and including, 4.1.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2026-15398, 9 Sep 2026
- The Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.22. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to bypass payment for paid events, fraudulently mark orders as completed, deplete ticket inventory, and trigger confirmation emails for tickets never purchased. This is exploitable by unauthenticated attackers because the wp_rest nonce is publicly emitted on every frontend page, and the order creation endpoint mints and returns an order_access_token to any caller possessing that nonce - giving unauthenticated users all credentials required to reach the privileged update_booking_status branch. CVE record
- CVE-2026-11821, 9 Sep 2026
- The Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to view, create, update, clone, and delete notification flow event automation workflows that should be restricted to administrators. CVE record
- CVE-2026-15406, 9 Sep 2026
- The Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with custom-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. CVE record
- CVE-2026-15667, 9 Sep 2026
- The Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The etn_manage_event capability is assigned to Contributors by default, meaning any Contributor-level user can set the malicious event_layout value via the REST API without any additional configuration. CVE record
- CVE-2026-12956, 9 Sep 2026
- The WP Event Solution (Eventin) plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 4.1.22 via the create_item() handler for the /wp-json/eventin/v2/orders REST endpoint. The endpoint's create_item_permissions_check() function only verifies a wp_rest nonce (which is leaked to every visitor through the etn-public script's localized_data_obj on every frontend page) and accepts a user-supplied 'status' value in prepare_item_for_database() with no whitelist validation. This makes it possible for unauthenticated attackers to create etn-order posts with status='completed' that are counted as sold by etn_get_sold_tickets_by_event(); because the auto-cleanup wp_schedule_single_event() in create_item() only fires for status='pending' orders, the forged completed orders persist indefinitely and exhaust ticket inventory. CVE record
- CVE-2026-84898, 5 Sep 2026
- The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with contributor-level access and above to include and execute arbitrary local PHP files. CVE record
- CVE-2026-84901, 5 Sep 2026
- The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy terms they should not be able to manage. CVE record
- CVE-2026-77694, 26 Aug 2026
- The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed to authorise on an order, allowing unauthenticated users to mark their own unpaid order as completed and be issued a valid paid ticket with no payment taken. CVE record
- CVE-2026-13172, 26 Aug 2026
- The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing unauthenticated users to retrieve draft, pending and private posts belonging to other users, along with the passwords and contents of password-protected ones. CVE record
- CVE-2026-13176, 21 Aug 2026
- The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify event ownership, allowing users with contributor-level access and above to trigger blind server-side requests to arbitrary hosts. CVE record
- CVE-2026-13174, 19 Aug 2026
- The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts. CVE record
- CVE-2026-13175, 19 Aug 2026
- The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with contributor-level access and above to alter or delete schedule entries created by other users. CVE record
- CVE-2026-13169, 19 Aug 2026
- The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned to a different author, allowing users with contributor-level access and above to alter, delete, or take over events created by other users including administrators. CVE record
- CVE-2026-13173, 19 Aug 2026
- The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users with contributor-level access and above to modify other users' roles and metadata. CVE record
- CVE-2026-13177, 12 Aug 2026
- The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing users with contributor-level access and above to read other customers' order data including personal information by iterating order identifiers. CVE record
- CVE-2026-13171, 12 Aug 2026
- The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticated users to create WordPress user accounts for arbitrary email addresses and inject order records. CVE record
- CVE-2026-13168, 12 Aug 2026
- The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users with contributor-level access and above to read other customers' personal data such as names and email addresses. CVE record
- CVE-2026-13170, 10 Aug 2026
- The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files. CVE record
- CVE-2026-13178, 30 Jul 2026
- The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment. CVE record
- CVE-2026-12924, 10 Jul 2026
- The Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter in all versions up to, and including, 4.1.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2025-14657, 9 Jan 2026
- The Eventin - Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'post_settings' function in all versions up to, and including, 4.0.51. This makes it possible for unauthenticated attackers to modify plugin settings. Furthermore, due to insufficient input sanitization and output escaping on the 'etn_primary_color' setting, this enables unauthenticated attackers to inject arbitrary web scripts that will execute whenever a user accesses a page where Eventin styles are loaded. CVE record
- CVE-2025-7813, 23 Aug 2025
- The Events Calendar, Event Booking, Registrations and Event Tickets - Eventin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.37 via the proxy_image function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. CVE record
- CVE-2025-4796, 8 Aug 2025
- The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due to the plugin not properly validating a user's identity or capability prior to updating their details like email in the 'Eventin\Speaker\Api\SpeakerController::update_item' function. This makes it possible for unauthenticated attackers with contributor-level and above permissions to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account. CVE record
- CVE-2025-3419, 8 May 2025
- The Event Manager, Events Calendar, Tickets, Registrations - Eventin plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 4.0.26 via the proxy_image() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. CVE-2025-47445 is a duplicate of this vulnerability. CVE record
- CVE-2025-1766, 20 Mar 2025
- The Event Manager, Events Calendar, Tickets, Registrations - Eventin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'payment_complete' function in all versions up to, and including, 4.0.24. This makes it possible for unauthenticated attackers to update the status of ticket payments to 'completed', possibly resulting in financial loss. CVE record
- CVE-2025-1770, 20 Mar 2025
- The Event Manager, Events Calendar, Tickets, Registrations - Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.24 via the 'style' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. CVE record
- CVE-2024-7149, 27 Sep 2024
- The Event Manager, Events Calendar, Tickets, Registrations - Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.8 via multiple style parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. CVE record
- CVE-2024-6033, 17 Jul 2024
- The Event Manager, Events Calendar, Tickets, Registrations - Eventin plugin for WordPress is vulnerable to unauthorized data importation due to a missing capability check on the 'import_file' function in all versions up to, and including, 4.0.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to import events, speakers, schedules and attendee data. CVE record
- CVE-2024-1122, 9 Feb 2024
- The Event Manager, Events Calendar, Events Tickets for WooCommerce - Eventin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_data() function in all versions up to, and including, 3.3.50. This makes it possible for unauthenticated attackers to export event data. CVE record
What to do if you run Eventin
If you run Eventin, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Eventin vulnerabilities
Free. We email you when a new vulnerability is published for Eventin, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.