The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'payment_complete' function in all versions up to, and including, 4.0.24. This makes it possible for unauthenticated attackers to update the status of ticket payments to 'completed', possibly resulting in financial loss.
Metrics
Affected Vendors & Products
References
History
Mon, 11 Aug 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Themewinter
Themewinter eventin |
|
CPEs | cpe:2.3:a:themewinter:eventin:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Themewinter
Themewinter eventin |
Thu, 20 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 05:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'payment_complete' function in all versions up to, and including, 4.0.24. This makes it possible for unauthenticated attackers to update the status of ticket payments to 'completed', possibly resulting in financial loss. | |
Title | Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Missing Authorization to Unauthenticated Payment Status Update | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-03-20T05:22:35.308Z
Updated: 2025-03-20T15:10:55.571Z
Reserved: 2025-02-27T19:26:34.096Z
Link: CVE-2025-1766

Updated: 2025-03-20T15:10:50.372Z

Status : Analyzed
Published: 2025-03-20T06:15:22.740
Modified: 2025-08-11T18:04:48.627
Link: CVE-2025-1766

No data.