WordPress Plugin Vulnerabilities

Eventin < 4.1.24 - Unauthenticated Ticket Price Rewrite via order_token

Description

The plugin does not prevent the token issued to a guest at checkout from being used to change that order's tickets afterwards, allowing unauthenticated users to replace a paid ticket with a free one and complete the order at no charge.

Proof of Concept

Affects Plugins

Fixed in 4.1.24

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Nir Yehoshua
Submitter
Nir Yehoshua
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-09-14 (about 2 days ago)
Added
2026-09-14 (about 1 day ago)
Last Updated
2026-09-14 (about 1 day ago)

Other