PT-2026-81964 · WordPress · Eventin

·

CVE-2026-77694

·

Published

2026-08-26

·

Updated

2026-08-26

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Eventin versions prior to 4.1.19
Description An issue exists where the software does not properly restrict the changes a guest checkout token can authorize on an order. This allows unauthenticated users to mark their own unpaid orders as completed, resulting in the issuance of a valid paid ticket without any payment being processed. The exploitation involves the order token variable.
Recommendations Update to version 4.1.19 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77694

Affected Products

Eventin