Executive brief
Eventin is a popular WordPress plugin used to manage event bookings and orders. The plugin fails to properly restrict access to order records, allowing any contributor-level user to view other customers' complete order data including names, email addresses, phone numbers, and payment details by simply changing order identifiers in API requests.
Technical details
This is an Insecure Direct Object Reference (IDOR) vulnerability in the Eventin REST API endpoint `/wp-json/eventin/v2/orders/{id}`. The plugin does not perform proper access control checks on the read operation for individual order records, though write operations are correctly protected. An attacker with contributor-level or above WordPress account credentials can enumerate order identifiers and retrieve sensitive customer personally identifiable information (PII) including full names, email addresses, phone numbers, and payment method details. The vulnerability requires authentication and knowledge of valid order IDs but allows complete disclosure of customer data across all orders in the system. The issue is fixed in version 4.1.20.
Affected products
- Eventin Eventin before 4.1.20
Timeline
- 2026-08-10: disclosed
- 2026-08-12: patched: Fixed in version 4.1.20