VYPR

Eventin

by WordPress

Source repositories

CVEs (30)

  • CVE-2023-49756MedDec 9, 2024
    risk 0.35cvss 5.4epss 0.01

    Missing Authorization vulnerability in Arraytics Eventin wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eventin: from n/a through <= 3.3.52.

  • CVE-2025-1766MedMar 20, 2025
    risk 0.34cvss 5.3epss 0.00

    The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'payment_complete' function in all versions up to, and including, 4.0.24. This makes it…

  • CVE-2026-13177MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing users with contributor-level access and above to read other customers' order data including personal information by iterating order identifiers.

  • CVE-2024-6033MedJul 17, 2024
    risk 0.28cvss 4.3epss 0.00

    The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized data importation due to a missing capability check on the 'import_file' function in all versions up to, and including, 4.0.4. This makes it possible for…

  • CVE-2024-1122MedFeb 9, 2024
    risk 0.27cvss 5.3epss 0.00

    The Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_data() function in all versions up to, and including, 3.3.50. This makes it possible…

  • CVE-2026-4109MedApr 14, 2026
    risk 0.21cvss 4.3epss 0.00

    The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the get_item_permissions_check() function in all versions up to, and including, 4.1.8. This…

  • CVE-2026-13173LowAug 19, 2026
    risk 0.18cvss 2.7epss 0.00

    The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users with contributor-level access and above to modify other users' roles and…

  • CVE-2026-13178HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment.

  • CVE-2026-13039MedJul 10, 2026
    risk 0.00cvss 5.3epss 0.00

    The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a regression in versions from 4.0.26 up to and including 4.1.15. This is due to the plugin not properly verifying that a user is…

  • CVE-2026-12924MedJul 10, 2026
    risk 0.00cvss 6.4epss 0.00

    The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter in all versions up to, and including, 4.1.15 due to insufficient input sanitization and output…

Page 2 of 2