CVE-2026-13178

The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-30 06:24

Updated : 2026-07-30 19:17


NVD link : CVE-2026-13178

Mitre link : CVE-2026-13178

CVE.ORG link : CVE-2026-13178


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key