CVE-2026-12956
Deferred Deferred - Pending Action

Missing Authorization in WP Event Solution Plugin

Vulnerability report for CVE-2026-12956, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: Wordfence

Description

The WP Event Solution (Eventin) plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 4.1.22 via the create_item() handler for the /wp-json/eventin/v2/orders REST endpoint. The endpoint's create_item_permissions_check() function only verifies a wp_rest nonce (which is leaked to every visitor through the etn-public script's localized_data_obj on every frontend page) and accepts a user-supplied 'status' value in prepare_item_for_database() with no whitelist validation. This makes it possible for unauthenticated attackers to create etn-order posts with status='completed' that are counted as sold by etn_get_sold_tickets_by_event(); because the auto-cleanup wp_schedule_single_event() in create_item() only fires for status='pending' orders, the forged completed orders persist indefinitely and exhaust ticket inventory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
eventin wp_event_solution to 4.1.22 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The WP Event Solution plugin for WordPress has a vulnerability in versions up to 4.1.22. It allows unauthenticated attackers to create fake orders with a 'completed' status by exploiting a missing authorization check in the REST endpoint. The plugin only verifies a nonce and accepts user-supplied status values without validation.

Detection Guidance

Check for unauthorized 'etn-order' posts with status='completed' in WordPress database. Inspect REST API logs for POST requests to /wp-json/eventin/v2/orders. Look for excessive ticket inventory depletion without corresponding sales.

Impact Analysis

Attackers can create fake orders that persist indefinitely, exhausting ticket inventory for events. This could lead to legitimate users being unable to purchase tickets or false reporting of sold-out events.

Compliance Impact

This vulnerability allows unauthenticated attackers to manipulate ticket orders by creating fake completed orders, which could lead to unauthorized data processing or financial discrepancies. This may violate GDPR principles of data integrity and accountability if personal data is involved, and could conflict with HIPAA requirements for secure transaction handling if health-related events are affected.

Mitigation Strategies

Update the WP Event Solution plugin to the latest version. Disable the /wp-json/eventin/v2/orders REST endpoint if not needed. Implement firewall rules to block unauthorized POST requests to this endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12956. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart