SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77694

MEDIUM · CVSS 5.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Eventin WordPress plugin prior to version 4.1.19 is vulnerable due to improper restrictions on guest checkout tokens, enabling unauthenticated users to mark their unpaid orders as completed and receive valid paid tickets without making any payment. This could lead to unauthorized access and potential financial loss for businesses relying on the plugin for event management. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-77694
Severity
MEDIUM
CVSS
5.3
EPSS
0.24%
WordPress

Original NVD Description

The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed to authorise on an order, allowing unauthenticated users to mark their own unpaid order as completed and be issued a valid paid ticket with no payment taken.