Junglewise Threat Intelligence

CVE-2026-13039: Arraytics Eventin authorization bypass in PaymentController

CVE-2026-13039 · Severity: medium · CVSS 5.3 · Published 2026-07-10

Vendors: Arraytics.

Executive brief

The Eventin plugin for WordPress, which manages event registrations and ticket sales, contains a security flaw that allows users to bypass payment requirements. An attacker can trick the system into marking unpaid ticket orders as 'completed' by submitting fake checkout identifiers. This results in the attacker receiving valid event tickets, QR codes, and confirmation emails without actually paying for them, potentially leading to financial loss for event organizers.

Technical details

A missing authorization check in the payment_complete() function within PaymentController.php allows for an authorization bypass. Unauthenticated attackers can exploit this by submitting a fabricated SureCart checkout ID or FluentCart cart hash to the vulnerable endpoint. Although the endpoint requires a wp_rest nonce, this token is publicly accessible as it is embedded in every public event page. This vulnerability is a regression, as a previous fix for the same component was not maintained in subsequent releases. Successful exploitation allows an attacker to manipulate order statuses to 'completed', triggering the delivery of attendee tickets and QR codes.

Affected products

  • arraytics Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) 4.0.26 - 4.1.15

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory

References