Authorization Flaw in Eventin Plugin for WordPress
CVE-2026-84906
Key Information:
Badges
What is CVE-2026-84906?
The Eventin plugin for WordPress, prior to version 4.1.24, has an authorization flaw that allows unauthenticated visitors to falsely mark unpaid orders as paid. This issue arises because the plugin solely relies on successful transaction reports from the payment gateway, without validating the transaction's amount, currency, or the associated order. As a result, it can be exploited to manipulate order statuses by replaying a single legitimate low-value payment transaction, posing a significant risk to online transactions and order integrity.
Affected Version(s)
Eventin 0 < 4.1.24
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved