Executive brief
The WP Event Solution (Eventin) plugin for WordPress provides event management and ticket sales functionality. An unauthenticated attacker can exploit a flaw in the orders REST API to forge fake "completed" ticket sales, artificially exhausting event ticket inventory and disrupting legitimate ticket purchases. This could lead to customer complaints, lost revenue, and reputational damage.
Technical details
The vulnerability is a missing authorization flaw in the create_item() handler of the /wp-json/eventin/v2/orders REST endpoint. The create_item_permissions_check() function relies solely on a wp_rest nonce that is publicly leaked in the etn-public script's localized data, providing no genuine authentication. Additionally, prepare_item_for_database() accepts a user-supplied 'status' parameter without whitelist validation, allowing attackers to create etn-order posts with status='completed'. Unlike pending orders (which are auto-cleaned up via wp_schedule_single_event()), completed orders persist indefinitely and are counted as sold by etn_get_sold_tickets_by_event(), allowing attackers to exhaust ticket inventory without authentication or user interaction.
Affected products
- WP Event Solution Eventin up to and including 4.1.22
Timeline
- 2026-09-09: disclosed