CVE-2026-15398
Deferred Deferred - Pending Action

Authorization Bypass in Eventin WordPress Plugin

Vulnerability report for CVE-2026-15398, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: Wordfence

Description

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.22. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to bypass payment for paid events, fraudulently mark orders as completed, deplete ticket inventory, and trigger confirmation emails for tickets never purchased. This is exploitable by unauthenticated attackers because the wp_rest nonce is publicly emitted on every frontend page, and the order creation endpoint mints and returns an order_access_token to any caller possessing that nonce β€” giving unauthenticated users all credentials required to reach the privileged update_booking_status branch.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
eventin event_calendar to 4.1.22 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Eventin WordPress plugin has an authorization bypass flaw in versions up to 4.1.22. It fails to verify user permissions for actions, allowing attackers with subscriber-level access or above to bypass payments, manipulate orders, deplete tickets, and trigger fake confirmation emails. Unauthenticated attackers can exploit this by using a publicly available wp_rest nonce to create orders and gain access to privileged functions.

Detection Guidance

Check WordPress installations for the Eventin plugin versions up to 4.1.22. Inspect server logs for unauthorized order creation or status updates. Look for unusual payment bypass attempts or ticket inventory depletion.

Impact Analysis

If you use this plugin, attackers could bypass payments for events, fraudulently mark orders as completed, deplete available tickets, or send confirmation emails for tickets that were never purchased. This could lead to financial losses, reputational damage, and operational disruptions for event organizers.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling unauthorized access to event booking data, which may include personal or sensitive information. Unauthorized bypass of payments or fraudulent order completions could lead to improper handling of financial or health-related data, violating regulatory requirements for data protection and integrity.

Mitigation Strategies

Update the Eventin plugin to the latest version beyond 4.1.22. Disable the plugin if updates are unavailable. Monitor for suspicious activity in order logs and restrict subscriber-level access to sensitive functions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15398. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart