CVE-2026-77702: Eventin < 4.1.24 - Unauthenticated Ticket Price Rewrite via order_token
Published Sep 16, 2026
·Updated
The Eventin WordPress plugin before 4.1.24 does not prevent the token issued to a guest at checkout from being used to change that order's tickets afterwards, allowing unauthenticated users to replace a paid ticket with a free one and complete the order at no charge.
Affected Software
1 affected component
Eventin WordPress plugin<4.1.24
Event History
Sep 16, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Sites using Eventin versions earlier than 4.1.24 are affected. The issue applies to guest checkout orders because it involves the token issued to a guest during checkout.
2
What does an attacker need to exploit it?
An attacker needs an order_token for a guest checkout order. No authentication is required to use that token to modify the order's tickets.
3
What is the impact of a successful exploit?
The attacker can replace a paid ticket in the affected order with a free ticket and complete the order without paying the original ticket price.