CVE-2026-13178
Eventin < 4.1.16 - Unauthenticated Payment Bypass via Order Status Manipulation
CVSS Score
7.5
EPSS Score
0.1%
EPSS Percentile
4th
The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment.
| Vendor | unknown |
| Product | eventin |
| Published | Jul 30, 2026 |
| Last Updated | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown eventin
Be the first to know when new high vulnerabilities affecting unknown eventin are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Eventin
0 < 4.1.16
References
Credits
Haitam Lazaar WPScan