CVE-2026-11821: Eventin <= 4.1.17 - Missing Authorization to Authenticated (Subscriber+) Notification Flow Management via notification-flow REST API Endpoint
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to view, create, update, clone, and delete notification flow event automation workflows that should be restricted to administrators.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)to a version that resolves this vulnerability.Fixed in 4.1.17 - Compensating control
Restrict access to the plugin’s notification-flow REST API endpoint so that only administrators can access notification flow event automation workflows (view/create/update/clone/delete).
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs an authenticated WordPress account with at least Subscriber-level access. Unauthenticated visitors are not described as able to exploit it.
What actions could a low-privileged user perform?
A Subscriber or higher-privileged user could view, create, update, clone, or delete notification-flow event automation workflows that should be limited to administrators.
Which installations are affected?
Eventin versions through 4.1.17, including 4.1.17, are affected. The issue concerns the notification-flow REST API endpoint.