WordPress 插件 The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) 存在授权绕过漏洞,影响所有包含 4.1.22 及更早的版本。该漏洞源于插件未能正确验证用户是否被授权执行特定操作。这使得拥有订阅者(Subscriber)级别或更高权限的已认证攻击者可以绕过付费活动的支付流程,擅自将订单标记为已完成,耗尽票务库存,并触发针对从未购买的门票的确认邮件。该漏洞也可被未认证攻击者利用,因为 认证令牌(n
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| arraytics | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce | 0 ~ 4.1.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15667 | 7.5 HIGH | Eventin <= 4.1.22 - Authenticated (Contirbutor+) Local File Inclusion via 'event_layout' P |
| CVE-2026-15406 | 7.5 HIGH | Eventin <= 4.1.22 - Authenticated (Custom+) Local File Inclusion via 'event_layout' Parame |
| CVE-2026-11821 | 5.4 MEDIUM | Eventin <= 4.1.17 - Missing Authorization to Authenticated (Subscriber+) Notification Flow |
| CVE-2026-12956 | 5.3 MEDIUM | Eventin <= 4.1.22 - Missing Authorization to Unauthenticated Arbitrary Order Creation and |
No comments yet