CVE · Medium

CVE-2026-12924 — Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.16

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12924 Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.16 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 4.1.16 4.1.16 2026-07-09

CVE-2026-12924

The Eventin plugin for WordPress contains a security flaw affecting all versions up to 4.1.15, which allows malicious users with contributor-level access or higher to insert unauthorized code into the 'etn_faq_content' field. This code can then be executed when users visit the affected page, posing a threat to website integrity and user safety.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.