Authorization Bypass in Event Calendar Plugin for WordPress from Eventin
CVE-2026-15398
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 September 2026
What is CVE-2026-15398?
The Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress contains an authorization bypass vulnerability due to inadequate user verification. Authenticated attackers, even those with minimal access (i.e., subscriber-level), can exploit this flaw to bypass payment mechanisms for paid events, fraudulently complete orders, deplete ticket inventory, and send confirmation emails for tickets that were never purchased. Furthermore, the vulnerability is exacerbated as unauthenticated users can exploit a publicly available nonce from the frontend, granting them access to create orders without authorization. This represents a significant security risk for event management and ticketing operations.
Affected Version(s)
Eventin β Event Calendar, Tickets, Registration, Booking & WooCommerce 0 <= 4.1.22