Impact
The Eventin WordPress plugin contains a missing capability check on the payment_complete function. As a result, unauthenticated attackers can change ticket payment status to 'completed' without authorization, creating opportunities for financial loss by approving payments that have not been legitimately processed.
Affected Systems
The vulnerability affects the Eventin event management plugin, versions 4.0.24 and earlier, used within WordPress installations.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests low exploitation probability at the time of analysis. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that attackers could directly request the payment_complete endpoint without authentication, allowing them to modify payment status.
OpenCVE Enrichment
EUVD