Unknown Eventin

6 known vulnerabilities in Unknown Eventin, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-84906 CVSS 5.3 medium The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming…
  • CVE-2026-84907 CVSS 3.7 low The Eventin WordPress plugin before 4.1.24 does not properly authorise order finalisation when its offline (local) payment method is…
  • CVE-2026-84905 CVSS 2.7 low The Eventin WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speaker, allowing users…
  • CVE-2026-77702 CVSS 5.3 medium The Eventin WordPress plugin before 4.1.24 does not prevent the token issued to a guest at checkout from being used to change that order's…
  • CVE-2026-84901 CVSS 4.9 medium The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing…
  • CVE-2026-84898 CVSS 6.6 medium The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file…