CVE-2026-13178: Eventin < 4.1.16 - Unauthenticated Payment Bypass via Order Status Manipulation
Published Jul 30, 2026
·Updated
The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment.
Affected Software
1 affected component
Eventin WordPress plugin<4.1.16
Event History
Jul 30, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:24 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-13178?
CVE-2026-13178 has a severity score of 7.5, indicating a high level of risk.
2
How do I fix CVE-2026-13178?
To fix CVE-2026-13178, update the Eventin WordPress plugin to version 4.1.16 or later.
3
What type of vulnerability is CVE-2026-13178?
CVE-2026-13178 is an unauthenticated payment bypass vulnerability that allows unauthorized order creation.
4
Who is affected by CVE-2026-13178?
Users of the Eventin WordPress plugin before version 4.1.16 are affected by CVE-2026-13178.
5
What can attackers achieve with CVE-2026-13178?
Attackers can create orders marked as paid without completing any payment due to the authorization failure in CVE-2026-13178.