Impact
The Eventin plugin for WordPress fails to properly authorize the REST endpoint used to create orders. The API accepts a user-supplied 'status' field without whitelisting, allowing an unauthenticated attacker to create completed orders that are counted as sold. This flaw can cause purchase volume to increase illegitimately, deplete ticket inventory, and effectively deny service to legitimate customers.
Affected Systems
Any WordPress site that has the Eventin plugin installed with a version of 4.1.22 or earlier is impacted. The vulnerability exists in the create_item() handler and its permission check within the /wp-json/eventin/v2/orders endpoint.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating limited evidence of exploitation in the wild. The attack vector is a publicly accessible REST route that does not require authentication; therefore, the barrier to exploitation is low and a site admin can exploit the flaw from any user or guest role.
OpenCVE Enrichment