Junglewise Threat Intelligence

CVE-2026-13171: Eventin WordPress plugin authorization bypass in waiting-list handler

CVE-2026-13171 · Severity: high · CVSS 8.2 · Published 2026-08-12

Vendors: Eventin.

Executive brief

The Eventin WordPress plugin for event management fails to verify user permissions on its waiting-list registration endpoint, allowing attackers to create arbitrary WordPress user accounts without authentication. This bypasses self-registration restrictions and enables account takeover, spam campaigns, or privilege escalation depending on the assigned user role and site configuration.

Technical details

The vulnerability is an access control bypass (CWE-284) in the waiting-list registration endpoint (`POST /wp-json/eventin/v2/orders/waiting-list`) and a secondary variant in the guest checkout route (`POST /wp-json/eventin/v2/orders`). The waiting-list handler performs no authorization checks and accepts event_id, customer email, and attendee details directly from unauthenticated requests, creating WordPress user accounts with the `etn-customer` role regardless of the site's "Anyone can register" setting. The guest checkout variant requires only a `wp_rest` nonce, which the plugin publicly exposes in event pages, eliminating effective authentication. No prior account, cookies, or user interaction are required. Exploitation results in account creation for arbitrary email addresses and injection of order records. The vulnerability is fixed in version 4.1.20.

Affected products

  • Eventin Eventin before 4.1.20

Timeline

  • 2026-08-10: disclosed
  • 2026-08-12: patched: Fixed in version 4.1.20

References