WordPress 插件 The WP Event Solution (Eventin) 在 4.1.22 及之前版本中,其 REST API 端点 的 处理器存在 缺失授权(Missing Authorization) 漏洞。 该端点的 函数仅验证 密钥(nonce),而此密钥会通过 脚本中的 泄露给所有前端页面的访问者。此外, 函数直接接受用户输入的 值,且未进行白名单校验。 这导致 未认证的攻击者 能够创建状态为 的 帖子。由于 函数会将这些订单计为已售出,而 中自动清理机制 仅对 的订单生效,因此这些伪造的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| arraytics | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce | 0 ~ 4.1.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15667 | 7.5 HIGH | Eventin <= 4.1.22 - Authenticated (Contirbutor+) Local File Inclusion via 'event_layout' P |
| CVE-2026-15406 | 7.5 HIGH | Eventin <= 4.1.22 - Authenticated (Custom+) Local File Inclusion via 'event_layout' Parame |
No comments yet