CVE-2026-77702
Eventin < 4.1.24 - Unauthenticated Ticket Price Rewrite via order_token
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Eventin WordPress plugin before 4.1.24 does not prevent the token issued to a guest at checkout from being used to change that order's tickets afterwards, allowing unauthenticated users to replace a paid ticket with a free one and complete the order at no charge.
| Vendor | unknown |
| Product | eventin |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown eventin
Be the first to know when new unknown vulnerabilities affecting unknown eventin are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Eventin
0 < 4.1.24
References
Credits
Nir Yehoshua WPScan