Junglewise Threat Intelligence

CVE-2026-12924: Arraytics Eventin Stored XSS in etn_faq_content parameter

CVE-2026-12924 · Severity: medium · CVSS 6.4 · Published 2026-07-10

Vendors: Arraytics.

Executive brief

The Eventin plugin for WordPress, which manages event calendars and ticket bookings, contains a security flaw that allows users with contributor-level access to inject malicious scripts into event pages. When other users or administrators view these pages, the scripts execute automatically in their browsers. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.

Technical details

The Eventin plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to a failure to properly sanitize and escape the 'etn_faq_content' parameter. This vulnerability exists in all versions up to and including 4.1.15. An authenticated attacker with contributor-level permissions or higher can inject arbitrary JavaScript into the FAQ content of an event. Because the payload is stored in the database and rendered without proper escaping, the script executes in the context of any user who views the affected event page. This can be used to hijack administrative sessions or perform unauthorized actions on the site. A patch was introduced in version 4.1.16.

Affected products

  • Arraytics Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) <= 4.1.15

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory

References