CVE · Medium

CVE-2026-13039 — Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.16

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-13039 Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.16 Missing Authorization Medium 5.3 < 4.1.16 4.1.16 2026-07-09

CVE-2026-13039

The Eventin plugin for WordPress contains a flaw that allows unauthorized users to complete unpaid ticket orders, effectively gaining access to paid events, tickets, and order confirmations, without making a legitimate payment. This is due to the plugin's failure to properly verify user authorization in the PaymentController's payment_complete function, allowing attackers to exploit this by submitting fake checkout or cart IDs. The vulnerability is present in versions 4.0.26 through 4.1.15, and is made worse by the fact that the necessary nonce is publicly accessible on event pages, eliminating the need for any WordPress credentials. This issue is a regression of a previously patched function and endpoint, which had been fixed but not sustained in subsequent releases.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.