WordPress Plugin Vulnerabilities

Eventin < 4.1.24 - Unauthenticated Payment Bypass via Stripe and PayPal Cross-Order Transaction Replay

Description

The plugin does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its amount, currency, or which order it belongs to, allowing unauthenticated visitors to mark unpaid orders of any value as paid by replaying the transaction of a single genuine low-value payment.

Proof of Concept

Affects Plugins

Fixed in 4.1.24

References

Miscellaneous

Original Researcher
cyberkareem
Submitter
cyberkareem
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-14 (about 2 days ago)
Added
2026-09-14 (about 1 day ago)
Last Updated
2026-09-14 (about 1 day ago)

Other