Unrated severityNVD Advisory· Published Jul 30, 2026· Updated Jul 30, 2026
Eventin < 4.1.16 - Unauthenticated Payment Bypass via Order Status Manipulation
CVE-2026-13178
Description
The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/09d6135f-b38c-4cfe-8a9f-5d79552c720c/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.