CVE-2026-77702: Unknown Eventin

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Eventin WordPress plugin before 4.1.24 does not prevent the token issued to a guest at checkout from being used to change that order's tickets afterwards, allowing unauthenticated users to replace a paid ticket with a free one and complete the order at no charge.

Affected products

  • Unknown Eventin: before 4.1.24 (fixed in 4.1.24)

Published 2026-09-16. Last modified 2026-09-17.