CVE-2026-84907: Eventin < 4.1.24 - Unauthenticated Order and Attendee Status Reset via Payment REST Endpoint

Published Sep 16, 2026
·
Updated

The Eventin WordPress plugin before 4.1.24 does not properly authorise order finalisation when its offline (local) payment method is enabled, relying on a nonce that is exposed to unauthenticated visitors and never checking that the caller owns the order, allowing unauthenticated attackers to reset any existing order and its attendees to a pending state and thereby invalidate paid tickets.

Affected Software

1 affected component
Eventin WordPress plugin<4.1.24

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Eventin WordPress plugin to a version that resolves this vulnerability.

    Fixed in 4.1.24
  2. Compensating control

    Disable/turn off the Eventin offline (local) payment method until the plugin is upgraded to 4.1.24

Event History

Sep 16, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Eventin installations running a version earlier than 4.1.24 are affected when the offline (local) payment method is enabled.

2

Does exploitation require a customer account or ownership of the targeted order?

No. The endpoint exposes its nonce to unauthenticated visitors and does not verify that the caller owns the order being finalised.

3

What can an attacker change?

An unauthenticated attacker can reset any existing order and its associated attendees to a pending state. This can invalidate tickets that were already paid for.

4

What should be done if an immediate upgrade is not possible?

Disable the offline (local) payment method, since the issue is described as occurring when that method is enabled. Upgrade Eventin to 4.1.24 or later when possible.

5

How can an administrator determine whether their site is at risk?

Check the installed Eventin version and whether offline (local) payments are enabled. Sites using a version before 4.1.24 with that payment method enabled are exposed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203