CVE-2026-77694 - Eventin < 4.1.19 - Unauthenticated Order Completion Without Payment via order_token
CVE ID :CVE-2026-77694
Published : Aug. 26, 2026, 6 a.m. | 29 minutes ago
Description :The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed to authorise on an order, allowing unauthenticated users to mark their own unpaid order as completed and be issued a valid paid ticket with no payment taken.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 26, 2026, 6 a.m. | 29 minutes ago
Description :The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed to authorise on an order, allowing unauthenticated users to mark their own unpaid order as completed and be issued a valid paid ticket with no payment taken.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...