Junglewise Threat Intelligence

CVE-2026-12956: WP Event Solution Eventin missing authorization in orders REST endpoint

CVE-2026-12956 · Severity: medium · CVSS 5.3 · Published 2026-09-09

Technologies: WP Event Solution Eventin. Vendors: WP Event Solution.

Executive brief

The WP Event Solution (Eventin) plugin for WordPress provides event management and ticket sales functionality. An unauthenticated attacker can exploit a flaw in the orders REST API to forge fake "completed" ticket sales, artificially exhausting event ticket inventory and disrupting legitimate ticket purchases. This could lead to customer complaints, lost revenue, and reputational damage.

Technical details

The vulnerability is a missing authorization flaw in the create_item() handler of the /wp-json/eventin/v2/orders REST endpoint. The create_item_permissions_check() function relies solely on a wp_rest nonce that is publicly leaked in the etn-public script's localized data, providing no genuine authentication. Additionally, prepare_item_for_database() accepts a user-supplied 'status' parameter without whitelist validation, allowing attackers to create etn-order posts with status='completed'. Unlike pending orders (which are auto-cleaned up via wp_schedule_single_event()), completed orders persist indefinitely and are counted as sold by etn_get_sold_tickets_by_event(), allowing attackers to exhaust ticket inventory without authentication or user interaction.

Affected products

  • WP Event Solution Eventin up to and including 4.1.22

Timeline

  • 2026-09-09: disclosed

References

Related threats