Authorization Bypass in Event Calendar Plugin for WordPress from Eventin
CVE-2026-15398

4.3MEDIUM

What is CVE-2026-15398?

The Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress contains an authorization bypass vulnerability due to inadequate user verification. Authenticated attackers, even those with minimal access (i.e., subscriber-level), can exploit this flaw to bypass payment mechanisms for paid events, fraudulently complete orders, deplete ticket inventory, and send confirmation emails for tickets that were never purchased. Furthermore, the vulnerability is exacerbated as unauthenticated users can exploit a publicly available nonce from the frontend, granting them access to create orders without authorization. This represents a significant security risk for event management and ticketing operations.

Affected Version(s)

Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce 0 <= 4.1.22

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.