Search
Search Results (5 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-13177 | 2 Eventin, Wordpress | 2 Eventin, Wordpress | 2026-08-13 | 4.3 Medium |
| The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing users with contributor-level access and above to read other customers' order data including personal information by iterating order identifiers. | ||||
| CVE-2026-13170 | 2 Eventin, Wordpress | 2 Eventin, Wordpress | 2026-08-13 | 7.2 High |
| The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files. | ||||
| CVE-2026-13171 | 2 Eventin, Wordpress | 2 Eventin, Wordpress | 2026-08-12 | 8.2 High |
| The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticated users to create WordPress user accounts for arbitrary email addresses and inject order records. | ||||
| CVE-2026-13168 | 2 Eventin, Wordpress | 2 Eventin, Wordpress | 2026-08-12 | 6.5 Medium |
| The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users with contributor-level access and above to read other customers' personal data such as names and email addresses. | ||||
| CVE-2026-13178 | 2 Eventin, Wordpress | 2 Eventin, Wordpress | 2026-07-30 | 7.5 High |
| The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment. | ||||
Page 1 of 1.