Impact
The vulnerability in the Eventin WordPress plugin allows an a paid ticket with a free one by reusing a guest order_token after checkout. The plugin does not enforce authentication or token validation for the ticket price update endpoint, enabling the attacker to arbitrarily modify the order cost. This leads to financial loss for event organizers and undermines ticket integrity.
Affected Systems
The affected product is the Eventin WordPress plugin before version 4.1.24. Any installation running 4.1.23 or earlier product versions are listed.
Risk and Exploitability
An attacker can exploit this flaw supplying a valid guest order_token. Because authentication is not required, any visitor who discovers or guesses a token can execute the request. The EPSS score of < 1 % indicates low overall exploitation probability, and it is not currently listed in the CISA KEV catalog, but the potential for financial loss remains. The attack vector is via the public order tokens and does not require privileged access or previous compromise.
OpenCVE Enrichment