Impact
The Eventin WordPress plugin before version 4.1.24 fails to properly authorise order finalisation when the offline payment method is enabled. The vulnerability relies on a nonce that is exposed to unauthenticated visitors and does not verify that the caller owns the order, allowing attackers to reset any existing order and its attendees to a pending state. This effectively invalidates paid tickets and undermines the integrity of the payment system.
Affected Systems
WordPress sites that have the Eventin plugin installed with a version earlier than 4.1.24 and have the offline (local) payment method enabled are affected. The flaw is specific to the payment REST endpoint of this plugin.
Risk and Exploitability
The vulnerability has a low exploit probability based on an EPSS score of less than 1%, and it is not listed in CISA’s KEV catalog. Exploitation requires no user authentication, with attackers sending requests to the exposed REST endpoint and providing the visible nonce. Because the flaw permits unauthenticated order resets, the risk profile is primarily an authorization bypass that can lead to financial loss and service disruption for event organizers.
OpenCVE Enrichment