VYPR

Eventin

by WordPress

Source repositories

CVEs (45)

  • CVE-2026-13176LowAug 21, 2026
    risk 0.18cvss 2.7epss 0.00

    The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify event ownership, allowing users with contributor-level access and above to trigger blind server-side requests to arbitrary hosts.

  • CVE-2026-13173LowAug 19, 2026
    risk 0.18cvss 2.7epss 0.00

    The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users with contributor-level access and above to modify other users' roles and…

  • CVE-2026-13178HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment.

  • CVE-2026-13039MedJul 10, 2026
    risk 0.00cvss 5.3epss 0.00

    The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a regression in versions from 4.0.26 up to and including 4.1.15. This is due to the plugin not properly verifying that a user is…

  • CVE-2026-12924MedJul 10, 2026
    risk 0.00cvss 6.4epss 0.00

    The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter in all versions up to, and including, 4.1.15 due to insufficient input sanitization and output…

Page 3 of 3