Themewinter
Themewinter Eventin: vulnerabilidades y CVE
Themewinter Eventin tiene 43 vulnerabilidades publicadas, 26 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE43
Últimos 12 meses26
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-84906 | Media (5.3) | 0.16% | — | 16 sept 2026 | The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its… |
| CVE-2026-84907 | Baja (3.7) | 0.25% | — | 16 sept 2026 | The Eventin WordPress plugin before 4.1.24 does not properly authorise order finalisation when its offline (local) payment method is enabled, relying on a nonce that is exposed to unauthenticated visitors and never… |
| CVE-2026-84905 | Baja (2.7) | 0.28% | — | 16 sept 2026 | The Eventin WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speaker, allowing users with contributor-level access and above to create new WordPress user accounts that… |
| CVE-2026-77702 | Media (5.3) | 0.30% | — | 16 sept 2026 | The Eventin WordPress plugin before 4.1.24 does not prevent the token issued to a guest at checkout from being used to change that order's tickets afterwards, allowing unauthenticated users to replace a paid ticket with… |
| CVE-2026-75983 | Alta (7.5) | 0.70% | — | 15 sept 2026 | The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the… |
| CVE-2026-15402 | Media (6.4) | 0.25% | — | 15 sept 2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter in all versions up… |
| CVE-2026-11821 | Media (5.4) | 0.18% | — | 9 sept 2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.17. This is due to the plugin not… |
| CVE-2026-15667 | Alta (7.5) | 0.80% | — | 9 sept 2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter… |
| CVE-2026-15406 | Alta (7.5) | 0.66% | — | 9 sept 2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter… |
| CVE-2026-12956 | Media (5.3) | 0.24% | — | 9 sept 2026 | The WP Event Solution (Eventin) plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 4.1.22 via the create_item() handler for the /wp-json/eventin/v2/orders REST endpoint. The… |
| CVE-2026-84901 | Media (4.9) | 0.33% | — | 5 sept 2026 | The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page… |
| CVE-2026-84898 | Media (6.6) | 0.43% | — | 5 sept 2026 | The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with contributor-level access and above to include and execute… |
| CVE-2026-77694 | Media (5.3) | 0.30% | — | 26 ago 2026 | The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed to authorise on an order, allowing unauthenticated users to mark their own unpaid order as completed… |
| CVE-2026-13172 | Media (5.3) | 0.31% | — | 26 ago 2026 | The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing unauthenticated users to retrieve draft, pending and… |
| CVE-2026-13176 | Baja (2.7) | 0.33% | — | 21 ago 2026 | The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify event ownership, allowing users with contributor-level access and above to trigger blind server-side… |
| CVE-2026-13173 | Baja (2.7) | 0.28% | — | 19 ago 2026 | The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users with… |
| CVE-2026-13169 | Alta (8.1) | 0.35% | — | 19 ago 2026 | The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned to a different author, allowing users with contributor-level access and… |
| CVE-2026-13177 | Media (4.3) | 0.25% | — | 12 ago 2026 | The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing users with contributor-level access and above to read other customers' order data including personal… |
| CVE-2026-13171 | Alta (8.2) | 0.33% | — | 12 ago 2026 | The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticated users to create WordPress user accounts for arbitrary email addresses… |
| CVE-2026-13168 | Media (6.5) | 0.37% | — | 12 ago 2026 | The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users with contributor-level access and above to read other customers' personal data such as names and… |
| CVE-2026-13170 | Alta (7.2) | 0.57% | — | 10 ago 2026 | The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary… |
| CVE-2026-13178 | Alta (7.5) | 0.36% | — | 30 jul 2026 | The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any… |
| CVE-2026-13039 | Media (5.3) | 0.35% | — | 10 jul 2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a regression in versions from 4.0.26 up to and including 4.1.15. This is… |
| CVE-2026-12924 | Media (6.4) | 0.36% | — | 10 jul 2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter in all versions up to, and… |
| CVE-2026-4109 | Media (4.3) | 0.28% | — | 14 abr 2026 | The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the get_item_permissions_check()… |
| CVE-2025-14657 | Alta (7.2) | 0.34% | — | 9 ene 2026 | The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'post_settings' function in… |
| CVE-2025-7813 | Alta (7.2) | 0.29% | — | 23 ago 2025 | The Events Calendar, Event Booking, Registrations and Event Tickets – Eventin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.37 via the proxy_image function.… |
| CVE-2025-4796 | Alta (8.8) | 0.59% | — | 8 ago 2025 | The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due to the plugin not properly validating a user's identity or capability… |
| CVE-2025-49321 | Media (6.1) | 0.26% | — | 27 jun 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arraytics Eventin wp-event-solution allows Reflected XSS.This issue affects Eventin: from n/a through <= 4.0.28. |
| CVE-2025-47539 | Crítica (9.8) | 28% | — | 23 may 2025 | Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a through <= 4.0.26. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.