CVE-2026-84907: Eventin < 4.1.24 - Unauthenticated Order and Attendee Status Reset via Payment REST Endpoint
The Eventin WordPress plugin before 4.1.24 does not properly authorise order finalisation when its offline (local) payment method is enabled, relying on a nonce that is exposed to unauthenticated visitors and never checking that the caller owns the order, allowing unauthenticated attackers to reset any existing order and its attendees to a pending state and thereby invalidate paid tickets.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Eventin WordPress pluginto a version that resolves this vulnerability.Fixed in 4.1.24 - Compensating control
Disable/turn off the Eventin offline (local) payment method until the plugin is upgraded to 4.1.24
Event History
Frequently Asked Questions
Which deployments are exposed?
Eventin installations running a version earlier than 4.1.24 are affected when the offline (local) payment method is enabled.
Does exploitation require a customer account or ownership of the targeted order?
No. The endpoint exposes its nonce to unauthenticated visitors and does not verify that the caller owns the order being finalised.
What can an attacker change?
An unauthenticated attacker can reset any existing order and its associated attendees to a pending state. This can invalidate tickets that were already paid for.
What should be done if an immediate upgrade is not possible?
Disable the offline (local) payment method, since the issue is described as occurring when that method is enabled. Upgrade Eventin to 4.1.24 or later when possible.
How can an administrator determine whether their site is at risk?
Check the installed Eventin version and whether offline (local) payments are enabled. Sites using a version before 4.1.24 with that payment method enabled are exposed.