Impact
The Eventin WordPress plugin permits contributors and higher level users to read detailed order records of other customers when they provide an order identifier. This lack of proper authorization control is an insecure direct object reference flaw that can reveal personal data contained in orders.
Affected Systems
All installations of Eventin WordPress plugin older than version 4.1.20 are affected. Any WordPress site that runs this plugin and grants contributor or higher role permissions to any user is potentially vulnerable.
Risk and Exploitability
The likely attack vector is an authenticated user exploiting an IDOR; based on the description, it is inferred that the attacker can enumerate order identifiers by simple iteration to extract other customers’ data. The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% shows a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, so no widespread known exploitation has been documented.
OpenCVE Enrichment