CVE

CVE-2026-13178 — Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.16

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-13178 Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.16 Authorization Bypass Through User-Controlled Key Unknown < 4.1.16 4.1.16 2026-07-30

CVE-2026-13178

Prior to version 4.1.16 of the Eventin plugin for WordPress, a security flaw allowed unauthorized individuals to initiate payments by creating orders with a "paid" status, bypassing the standard authorization process for order creation. This vulnerability was due to inadequate validation of user input regarding order status. As a result, unauthenticated users could exploit this weakness to create paid orders without undergoing any payment processing.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.