« Volver al listado

Themewinter

Themewinter Eventin: vulnerabilidades y CVE

Themewinter Eventin tiene 43 vulnerabilidades publicadas, 26 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE43
Últimos 12 meses26
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-84906Media (5.3)0.16%—16 sept 2026
The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its…
CVE-2026-84907Baja (3.7)0.25%—16 sept 2026
The Eventin WordPress plugin before 4.1.24 does not properly authorise order finalisation when its offline (local) payment method is enabled, relying on a nonce that is exposed to unauthenticated visitors and never…
CVE-2026-84905Baja (2.7)0.28%—16 sept 2026
The Eventin WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speaker, allowing users with contributor-level access and above to create new WordPress user accounts that…
CVE-2026-77702Media (5.3)0.30%—16 sept 2026
The Eventin WordPress plugin before 4.1.24 does not prevent the token issued to a guest at checkout from being used to change that order's tickets afterwards, allowing unauthenticated users to replace a paid ticket with…
CVE-2026-75983Alta (7.5)0.70%—15 sept 2026
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the…
CVE-2026-15402Media (6.4)0.25%—15 sept 2026
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter in all versions up…
CVE-2026-11821Media (5.4)0.18%—9 sept 2026
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.17. This is due to the plugin not…
CVE-2026-15667Alta (7.5)0.80%—9 sept 2026
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter…
CVE-2026-15406Alta (7.5)0.66%—9 sept 2026
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter…
CVE-2026-12956Media (5.3)0.24%—9 sept 2026
The WP Event Solution (Eventin) plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 4.1.22 via the create_item() handler for the /wp-json/eventin/v2/orders REST endpoint. The…
CVE-2026-84901Media (4.9)0.33%—5 sept 2026
The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page…
CVE-2026-84898Media (6.6)0.43%—5 sept 2026
The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with contributor-level access and above to include and execute…
CVE-2026-77694Media (5.3)0.30%—26 ago 2026
The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed to authorise on an order, allowing unauthenticated users to mark their own unpaid order as completed…
CVE-2026-13172Media (5.3)0.31%—26 ago 2026
The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing unauthenticated users to retrieve draft, pending and…
CVE-2026-13176Baja (2.7)0.33%—21 ago 2026
The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify event ownership, allowing users with contributor-level access and above to trigger blind server-side…
CVE-2026-13173Baja (2.7)0.28%—19 ago 2026
The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users with…
CVE-2026-13169Alta (8.1)0.35%—19 ago 2026
The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned to a different author, allowing users with contributor-level access and…
CVE-2026-13177Media (4.3)0.25%—12 ago 2026
The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing users with contributor-level access and above to read other customers' order data including personal…
CVE-2026-13171Alta (8.2)0.33%—12 ago 2026
The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticated users to create WordPress user accounts for arbitrary email addresses…
CVE-2026-13168Media (6.5)0.37%—12 ago 2026
The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users with contributor-level access and above to read other customers' personal data such as names and…
CVE-2026-13170Alta (7.2)0.57%—10 ago 2026
The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary…
CVE-2026-13178Alta (7.5)0.36%—30 jul 2026
The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any…
CVE-2026-13039Media (5.3)0.35%—10 jul 2026
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a regression in versions from 4.0.26 up to and including 4.1.15. This is…
CVE-2026-12924Media (6.4)0.36%—10 jul 2026
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter in all versions up to, and…
CVE-2026-4109Media (4.3)0.28%—14 abr 2026
The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the get_item_permissions_check()…
CVE-2025-14657Alta (7.2)0.34%—9 ene 2026
The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'post_settings' function in…
CVE-2025-7813Alta (7.2)0.29%—23 ago 2025
The Events Calendar, Event Booking, Registrations and Event Tickets – Eventin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.37 via the proxy_image function.…
CVE-2025-4796Alta (8.8)0.59%—8 ago 2025
The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due to the plugin not properly validating a user's identity or capability…
CVE-2025-49321Media (6.1)0.26%—27 jun 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arraytics Eventin wp-event-solution allows Reflected XSS.This issue affects Eventin: from n/a through <= 4.0.28.
CVE-2025-47539Crítica (9.8)28%—23 may 2025
Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a through <= 4.0.26.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services4
  2. T1059 Command and Scripting Interpreter2
  3. T1068 Exploitation for Privilege Escalation1
  4. T1136 Create Account1
  5. T1190 Exploit Public-Facing Application1
  6. T1565.001 Stored Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Themewinter