Impact
The vulnerability in the Eventin WordPress plugin allows an attacker to replace a paid ticket with a free one by reusing a guest order_token after checkout. This is a CWE-862 Authorization Bypass vulnerability. The plugin does not enforce authentication or token validation for the ticket price update endpoint, enabling the attacker to arbitrarily modify the order cost. This leads to financial loss for event organizers and undermines ticket integrity.
Affected Systems
The affected product is the Eventin WordPress plugin before version 4.1.24. Any installation running 4.1.23 or earlier product versions are listed.
Risk and Exploitability
An attacker can exploit this flaw by supplying a valid guest order_token. Because authentication is not required, any visitor who discovers or guesses a token can execute the request. The CVSS score of 5.3 reflects moderate severity, while the EPSS score of < 1 % indicates a low overall exploitation probability. The flaw is not listed in the CISA KEV catalog, but it can result in financial loss. The likely attack vector is via the public order tokens and does not require privileged access or prior compromise.
OpenCVE Enrichment