Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce < 4.1.21 - Authenticated (Contributor+) Server-Side Request Forgery
medium
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to 4.1.21. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating...
- CVSS:
- 6.4
- Affected:
- up to 4.1.21
- Fixed in:
- 4.1.21
- Disclosed:
- Aug 24, 2026
CVE-2026-13176 on NVD →
Eventin <= 4.1.20 - Insecure Direct Object Reference to Authenticated (Contributor+) Schedule Deletion and Modification
medium
The Eventin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.1.20. This is due to the permission check reading the subject ID from the request body parameter `ids` while the handler read it from the URL parameter `id`, allowing an attacker to authorize against t...
- CVSS:
- 6.3
- Affected:
- up to 4.1.20
- Fixed in:
- 4.1.21
- Disclosed:
- Aug 17, 2026
CVE-2026-13175 on NVD →
Eventin <= 4.1.20 - Authenticated (Contributor+) Insecure Direct Object Reference to Speaker Account Deletion
medium
The Eventin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.1.20. This is due to the permission check preferring the `ids` body parameter over the URL path `id`, allowing the check to pass against the attacker's own account while the deletion executed against t...
- CVSS:
- 4.3
- Affected:
- up to 4.1.20
- Fixed in:
- 4.1.21
- Disclosed:
- Aug 17, 2026
CVE-2026-13174 on NVD →
Eventin <= 4.1.20 - Missing Authorization
medium
The Eventin plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 4.1.20. This is due to a missing capability check on a function. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 4.1.20
- Fixed in:
- 4.1.21
- Disclosed:
- Aug 17, 2026
CVE-2026-13173 on NVD →
Eventin <= 4.1.20 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Event Modification, Deletion and Ownership Takeover
medium
The Eventin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.1.20. This is due to a mismatch between the parameter read during authorization (body `ids`) and the parameter read during execution (URL `id`), allowing a body-supplied `ids` value to satisfy the owne...
- CVSS:
- 4.3
- Affected:
- up to 4.1.20
- Fixed in:
- 4.1.21
- Disclosed:
- Aug 17, 2026
CVE-2026-13169 on NVD →
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce < 4.1.20 - Authenticated (Contributor+) Information Exposure
medium
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to 4.1.20. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 4.1.20
- Fixed in:
- 4.1.20
- Disclosed:
- Aug 13, 2026
CVE-2026-13177 on NVD →
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce < 4.1.20 - Authenticated (Contributor+) Information Exposure
medium
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to 4.1.20. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 4.1.20
- Fixed in:
- 4.1.20
- Disclosed:
- Aug 13, 2026
CVE-2026-13168 on NVD →
Event SOlution <= 4.1.18 - Authenticated (Customer+) Information Exposure
medium
The Event SOlution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.1.18. This makes it possible for authenticated attackers, with customer-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 4.1.18
- Fixed in:
- 4.1.19
- Disclosed:
- Aug 13, 2026
CVE-2026-28174 on NVD →
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.19 - Authenticated (Customer+) Arbitrary Content Deletion
medium
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.1.19. This makes it possible for authenticated attackers, with Custom-level access and above, to de...
- CVSS:
- 4.3
- Affected:
- up to 4.1.19
- Fixed in:
- 4.1.20
- Disclosed:
- Aug 13, 2026
CVE-2026-28173 on NVD →
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce < 4.1.20 - Unauthenticated User Account Creation
medium
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to user account creation in all versions up to 4.1.20 (exclusive).This makes it possible for unauthenticated attackers to create user accounts when user registration is disabled.
- CVSS:
- 5.3
- Affected:
- up to 4.1.20
- Fixed in:
- 4.1.20
- Disclosed:
- Aug 10, 2026
CVE-2026-13171 on NVD →
Eventin <= 4.1.19 - Authenticated (Editor+) Local File Inclusion
medium
The Eventin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.19. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can b...
- CVSS:
- 6.6
- Affected:
- up to 4.1.19
- Fixed in:
- 4.1.20
- Disclosed:
- Aug 6, 2026
CVE-2026-13170 on NVD →
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.9 - Missing Authorization
medium
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.1.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.1.9
- Fixed in:
- 4.1.10
- Disclosed:
- Aug 5, 2026
CVE-2026-66451 on NVD →
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce < 4.1.16 - Unauthenticated Payment Bypass
medium
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to 4.1.16 (exclusive). This makes it possible for unauthenticated attackers to bypass payments by manipulating order statuses.
- CVSS:
- 5.3
- Affected:
- up to 4.1.16
- Fixed in:
- 4.1.16
- Disclosed:
- Aug 4, 2026
CVE-2026-13178 on NVD →
Eventin <= 4.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'etn_faq_content' Parameter
medium
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter in all versions up to, and including, 4.1.15 due to insufficient input sanitization and output escaping. This makes it possible for authe...
- CVSS:
- 6.4
- Affected:
- up to 4.1.15
- Fixed in:
- 4.1.16
- Disclosed:
- Jul 9, 2026
CVE-2026-12924 on NVD →
Eventin 4.0.26 - 4.1.15 - Missing Authorization to Unauthenticated Payment Bypass via REST API
medium
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a regression in versions from 4.0.26 up to and including 4.1.15. This is due to the plugin not properly verifying that a user is authorized to perform an action in the payme...
- CVSS:
- 5.3
- Affected:
- 4.0.26 – 4.1.15
- Fixed in:
- 4.1.16
- Disclosed:
- Jul 9, 2026
CVE-2026-13039 on NVD →
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) <= 4.1.12 - Missing Authorization
medium
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1.12. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.1.12
- Fixed in:
- 4.1.13
- Disclosed:
- Jun 15, 2026
CVE-2025-68045 on NVD →
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) <= 4.1.8 - Missing Authorization
medium
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.1.8
- Fixed in:
- 4.1.9
- Disclosed:
- Apr 29, 2026
CVE-2026-40776 on NVD →
Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) <= 4.1.8 Missing Authorization to Authenticated (Subscriber+) Order Information Exposure
medium
The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the get_item_permissions_check() function in all versions up to, and including, 4.1.8. This makes it possible for authenticated attacke...
- CVSS:
- 4.3
- Affected:
- up to 4.1.8
- Fixed in:
- 4.1.9
- Disclosed:
- Apr 13, 2026
CVE-2026-4109 on NVD →
Eventin <= 4.1.3 - Authenticated (Contributor+) PHP Object Injection
high
The Eventin plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.1.3 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable soft...
- CVSS:
- 7.5
- Affected:
- up to 4.1.3
- Fixed in:
- 4.1.4
- Disclosed:
- Jan 22, 2026
CVE-2025-68047 on NVD →
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) [wp-event-solution] <= 4.1.1 (unfixed)
unknown
[en] Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a through <= 4.1.1.
- Affected:
- up to 4.1.1
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2025-68047 on NVD →
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) [wp-event-solution] < 4.0.52
unknown
[en] The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'post_settings' function in all versions up to, and including, 4.0.51. This makes it possible for unauthenticated attackers...
- Affected:
- up to 4.0.52
- Fixed in:
- 4.0.52
- Disclosed:
- Jan 9, 2026
CVE-2025-14657 on NVD →
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) <= 4.0.51 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting via 'post_settings'
high
The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'post_settings' function in all versions up to, and including, 4.0.51. This makes it possible for unauthenticated attackers to mo...
- CVSS:
- 7.2
- Affected:
- up to 4.0.51
- Fixed in:
- 4.0.52
- Disclosed:
- Jan 8, 2026
CVE-2025-14657 on NVD →
Event Manager, Events Calendar, Booking, Registrations and Tickets – Eventin <= 4.0.37 - Unauthenticated Server-Side Request Forgery
high
The Events Calendar, Event Booking, Registrations and Event Tickets – Eventin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.37 via the proxy_image function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations orig...
- CVSS:
- 7.2
- Affected:
- up to 4.0.37
- Fixed in:
- 4.0.38
- Disclosed:
- Aug 22, 2025
CVE-2025-7813 on NVD →
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) [wp-event-solution] < 4.0.32
unknown
[en] Deserialization of Untrusted Data vulnerability in Arraytics Eventin allows Object Injection. This issue affects Eventin: from n/a through 4.0.31.
- Affected:
- up to 4.0.32
- Fixed in:
- 4.0.32
- Disclosed:
- Aug 14, 2025
CVE-2025-49869 on NVD →
Eventin <= 4.0.31 - Authenticated (Contributor+) PHP Object Injection
high
The Eventin plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.0.31 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable sof...
- CVSS:
- 7.5
- Affected:
- up to 4.0.31
- Fixed in:
- 4.0.32
- Disclosed:
- Aug 13, 2025
CVE-2025-49869 on NVD →
Eventin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover
high
The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due to the plugin not properly validating a user's identity or capability prior to updating their details like email in the 'Eventin\Speaker\Api\SpeakerController::update_ite...
- CVSS:
- 8.8
- Affected:
- up to 4.0.34
- Fixed in:
- 4.0.35
- Disclosed:
- Aug 8, 2025
CVE-2025-4796 on NVD →
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) [wp-event-solution] < 4.0.29
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arraytics Eventin allows Reflected XSS. This issue affects Eventin: from n/a through 4.0.28.
- Affected:
- up to 4.0.29
- Fixed in:
- 4.0.29
- Disclosed:
- Jun 27, 2025
CVE-2025-49321 on NVD →
Eventin <= 4.0.28 - Reflected Cross-Site Scripting
medium
The Event Manager, Events Calendar, Booking, Registrations and Tickets – Eventin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.0.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject ar...
- CVSS:
- 6.1
- Affected:
- up to 4.0.28
- Fixed in:
- 4.0.29
- Disclosed:
- Jun 23, 2025
CVE-2025-49321 on NVD →
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) [wp-event-solution] < 4.0.27
unknown
[en] Incorrect Privilege Assignment vulnerability in Themewinter Eventin allows Privilege Escalation. This issue affects Eventin: from n/a through 4.0.26.
- Affected:
- up to 4.0.27
- Fixed in:
- 4.0.27
- Disclosed:
- May 23, 2025
CVE-2025-47539 on NVD →
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) [wp-event-solution] < 4.0.27
unknown
[en] Relative Path Traversal vulnerability in Themewinter Eventin allows Path Traversal.This issue affects Eventin: from n/a through 4.0.26.
- Affected:
- up to 4.0.27
- Fixed in:
- 4.0.27
- Disclosed:
- May 14, 2025
CVE-2025-47445 on NVD →
Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.26 - Unauthenticated Arbitrary File Read
high
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 4.0.26 via the proxy_image() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which ca...
- CVSS:
- 7.5
- Affected:
- up to 4.0.26
- Fixed in:
- 4.0.27
- Disclosed:
- May 7, 2025
CVE-2025-3419 on NVD →
Eventin <= 4.0.26 - Missing Authorization to Unauthenticated Privilege Escalation
critical
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the import_items() function in all versions up to, and including, 4.0.26. This makes it possible for unauthenticated attackers to import users that can have...
- CVSS:
- 9.8
- Affected:
- up to 4.0.26
- Fixed in:
- 4.0.27
- Disclosed:
- May 7, 2025
CVE-2025-47539 on NVD →
Eventin <= 4.0.25 - Authenticated (Contributor+) Local File Inclusion
high
The Eventin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.25 via the 'events_tab' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any...
- CVSS:
- 8.8
- Affected:
- up to 4.0.25
- Fixed in:
- 4.0.26
- Disclosed:
- Apr 16, 2025
CVE-2025-39584 on NVD →
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) [wp-event-solution] < 4.0.26
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themewinter Eventin allows PHP Local File Inclusion. This issue affects Eventin: from n/a through 4.0.25.
- Affected:
- up to 4.0.26
- Fixed in:
- 4.0.26
- Disclosed:
- Apr 16, 2025
CVE-2025-39584 on NVD →
Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Authenticated (Contributor+) Local File Inclusion
high
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.24 via the 'style' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbi...
- CVSS:
- 8.8
- Affected:
- up to 4.0.24
- Fixed in:
- 4.0.25
- Disclosed:
- Mar 19, 2025
CVE-2025-1770 on NVD →
Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Missing Authorization to Unauthenticated Payment Status Update
medium
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'payment_complete' function in all versions up to, and including, 4.0.24. This makes it possible for unauthenticated attackers to update t...
- CVSS:
- 5.3
- Affected:
- up to 4.0.24
- Fixed in:
- 4.0.25
- Disclosed:
- Mar 19, 2025
CVE-2025-1766 on NVD →
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) [wp-event-solution] < 4.0.21
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themewinter Eventin allows PHP Local File Inclusion. This issue affects Eventin: from n/a through 4.0.20.
- Affected:
- up to 4.0.21
- Fixed in:
- 4.0.21
- Disclosed:
- Feb 25, 2025
CVE-2025-26964 on NVD →
Eventin <= 4.0.20 - Authenticated (Contributor+) Local File Inclusion
high
The Eventin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.20. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This...
- CVSS:
- 8.8
- Affected:
- up to 4.0.20
- Fixed in:
- 4.0.21
- Disclosed:
- Feb 23, 2025
CVE-2025-26964 on NVD →
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) [wp-event-solution] < 4.0.9
unknown
[en] Path Traversal: '.../...//' vulnerability in Themewinter Eventin allows Path Traversal.This issue affects Eventin: from n/a through 4.0.7.
- Affected:
- up to 4.0.9
- Fixed in:
- 4.0.9
- Disclosed:
- Dec 31, 2024
CVE-2024-56213 on NVD →
Eventin <= 4.0.7 - Authenticated (Contributor+) Local File Inclusion
high
The Eventin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.7. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This c...
- CVSS:
- 8.8
- Affected:
- up to 4.0.7
- Fixed in:
- 4.0.9
- Disclosed:
- Dec 19, 2024
CVE-2024-56213 on NVD →
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) [wp-event-solution] < 3.3.53
unknown
[en] Missing Authorization vulnerability in Themewinter Eventin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eventin: from n/a through 3.3.52.
- Affected:
- up to 3.3.53
- Fixed in:
- 3.3.53
- Disclosed:
- Dec 9, 2024
CVE-2023-49756 on NVD →
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) [wp-event-solution] < 4.0.9
unknown
[en] The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.8 via multiple style parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and exec...
- Affected:
- up to 4.0.9
- Fixed in:
- 4.0.9
- Disclosed:
- Sep 27, 2024
CVE-2024-7149 on NVD →
Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.8 - Authenticated (Contributor+) Local File Inclusion
high
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.8 via multiple style parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute a...
- CVSS:
- 8.8
- Affected:
- up to 4.0.8
- Fixed in:
- 4.0.9
- Disclosed:
- Sep 26, 2024
CVE-2024-7149 on NVD →
Eventin <= 4.0.5 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Eventin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will exe...
- CVSS:
- 6.4
- Affected:
- up to 4.0.5
- Fixed in:
- 4.0.6
- Disclosed:
- Aug 1, 2024
CVE-2024-39648 on NVD →
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) [wp-event-solution] < 4.0.6
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.This issue affects Eventin: from n/a through 4.0.5.
- Affected:
- up to 4.0.6
- Fixed in:
- 4.0.6
- Disclosed:
- Aug 1, 2024
CVE-2024-39648 on NVD →
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) [wp-event-solution] < 4.0.0
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.This issue affects Eventin: from n/a through 3.3.57.
- Affected:
- up to 4.0.0
- Fixed in:
- 4.0.0
- Disclosed:
- Jul 21, 2024
CVE-2024-37507 on NVD →
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) [wp-event-solution] < 4.0.5
unknown
[en] The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized data importation due to a missing capability check on the 'import_file' function in all versions up to, and including, 4.0.4. This makes it possible for authenticated attackers, with Contributor-...
- Affected:
- up to 4.0.5
- Fixed in:
- 4.0.5
- Disclosed:
- Jul 17, 2024
CVE-2024-6033 on NVD →
Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.4 - Missing Authorization to Authenticated (Contributor+) Event Data Import
medium
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized data importation due to a missing capability check on the 'import_file' function in all versions up to, and including, 4.0.4. This makes it possible for authenticated attackers, with Contributor-level...
- CVSS:
- 4.3
- Affected:
- up to 4.0.4
- Fixed in:
- 4.0.5
- Disclosed:
- Jul 16, 2024
CVE-2024-6033 on NVD →
Eventin <= 3.3.57 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Eventin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.57 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will ex...
- CVSS:
- 6.4
- Affected:
- up to 3.3.57
- Fixed in:
- 4.0.0
- Disclosed:
- Jul 4, 2024
CVE-2024-37507 on NVD →
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) [wp-event-solution] < 3.3.51
unknown
[en] The Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_data() function in all versions up to, and including, 3.3.50. This makes it possible for unauthenticated attackers to export...
- Affected:
- up to 3.3.51
- Fixed in:
- 3.3.51
- Disclosed:
- Feb 9, 2024
CVE-2024-1122 on NVD →
Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin <= 3.3.50 - Missing Authorization to Unauthenticated Events Export
medium
The Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_data() function in all versions up to, and including, 3.3.50. This makes it possible for unauthenticated attackers to export even...
- CVSS:
- 5.3
- Affected:
- up to 3.3.50
- Fixed in:
- 3.3.51
- Disclosed:
- Feb 8, 2024
CVE-2024-1122 on NVD →
Eventin <= 3.3.52 - Missing Authorization
medium
The Eventin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the import_file() function in versions up to, and including, 3.3.52. This makes it possible for authenticated attackers, with subscriber-level access and above, to import events.
- CVSS:
- 4.3
- Affected:
- up to 3.3.52
- Fixed in:
- 3.3.53
- Disclosed:
- Dec 4, 2023
CVE-2023-49756 on NVD →
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) [wp-event-solution] < 4.0.27
unknown
- Affected:
- up to 4.0.27
- Fixed in:
- 4.0.27
CVE-2025-3419 on NVD →
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) [wp-event-solution] < 4.0.25
unknown
- Affected:
- up to 4.0.25
- Fixed in:
- 4.0.25
CVE-2025-1766 on NVD →
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) [wp-event-solution] < 4.0.35
unknown
- Affected:
- up to 4.0.35
- Fixed in:
- 4.0.35
CVE-2025-4796 on NVD →
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) [wp-event-solution] < 4.0.25
unknown
- Affected:
- up to 4.0.25
- Fixed in:
- 4.0.25
CVE-2025-1770 on NVD →