Extension WordPress

Vulnérabilités Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

Cette page rassemble les failles publiées pour Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered), leurs plages de versions affectées et les correctifs signalés dans la base locale.

24Vulnérabilités
1Critiques
24Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

24 fiches

CVE-2026-12924 Moyenne · 6,4
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

Eventin <= 4.1.15 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'etn_faq_content' Parameter

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter in all versions up to, and including, 4.1.15 due to insufficient input sanitization…

Versions affectées

*-4.1.15

Correctif

4.1.16

Publication

09/07/2026

CVE-2026-13039 Moyenne · 5,3
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

Eventin 4.0.26 – 4.1.15 – Missing Authorization to Unauthenticated Payment Bypass via REST API

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a regression in versions from 4.0.26 up to and including 4.1.15. This is due to the…

Versions affectées

4.0.26-4.1.15

Correctif

4.1.16

Publication

09/07/2026

CVE-2025-68045 Moyenne · 5,3
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) <= 4.1.12 – Missing Authorization

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1.12. This makes…

Versions affectées

*-4.1.12

Correctif

4.1.13

Publication

15/06/2026

CVE-2026-40776 Moyenne · 5,3
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) <= 4.1.8 – Missing Authorization

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1.8. This makes…

Versions affectées

*-4.1.8

Correctif

4.1.9

Publication

29/04/2026

CVE-2026-4109 Moyenne · 4,3
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) <= 4.1.8 Missing Authorization to Authenticated (Subscriber+) Order Information Exposure

The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the get_item_permissions_check() function in all versions up to, and…

Versions affectées

*-4.1.8

Correctif

4.1.9

Publication

13/04/2026

CVE-2025-68047 Élevée · 7,5
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

Eventin <= 4.1.3 – Authenticated (Contributor+) PHP Object Injection

The Eventin plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.1.3 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a…

Versions affectées

*-4.1.3

Correctif

4.1.4

Publication

22/01/2026

CVE-2025-14657 Élevée · 7,2
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) <= 4.0.51 – Missing Authorization to Unauthenticated Stored Cross-Site Scripting via 'post_settings'

The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'post_settings' function in all versions up to, and including,…

Versions affectées

*-4.0.51

Correctif

4.0.52

Publication

08/01/2026

CVE-2025-7813 Élevée · 7,2
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

Event Manager, Events Calendar, Booking, Registrations and Tickets – Eventin <= 4.0.37 – Unauthenticated Server-Side Request Forgery

The Events Calendar, Event Booking, Registrations and Event Tickets – Eventin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.37 via the proxy_image function. This makes it possible for unauthenticated…

Versions affectées

*-4.0.37

Correctif

4.0.38

Publication

22/08/2025

CVE-2025-49869 Élevée · 7,5
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

Eventin <= 4.0.31 – Authenticated (Contributor+) PHP Object Injection

The Eventin plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.0.31 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a…

Versions affectées

*-4.0.31

Correctif

4.0.32

Publication

13/08/2025

CVE-2025-4796 Élevée · 8,8
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

Eventin <= 4.0.34 – Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover

The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due to the plugin not properly validating a user's identity or capability prior to updating…

Versions affectées

*-4.0.34

Correctif

4.0.35

Publication

08/08/2025

CVE-2025-49321 Moyenne · 6,1
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

Eventin <= 4.0.28 – Reflected Cross-Site Scripting

The Event Manager, Events Calendar, Booking, Registrations and Tickets – Eventin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.0.28 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-4.0.28

Correctif

4.0.29

Publication

23/06/2025

CVE-2025-3419 Élevée · 7,5
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.26 – Unauthenticated Arbitrary File Read

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 4.0.26 via the proxy_image() function. This makes it possible for unauthenticated attackers to…

Versions affectées

*-4.0.26

Correctif

4.0.27

Publication

07/05/2025

CVE-2025-47539 Critique · 9,8
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

Eventin <= 4.0.26 – Missing Authorization to Unauthenticated Privilege Escalation

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the import_items() function in all versions up to, and including, 4.0.26. This makes it…

Versions affectées

*-4.0.26

Correctif

4.0.27

Publication

07/05/2025

CVE-2025-39584 Élevée · 8,8
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

Eventin <= 4.0.25 – Authenticated (Contributor+) Local File Inclusion

The Eventin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.25 via the 'events_tab' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute…

Versions affectées

*-4.0.25

Correctif

4.0.26

Publication

16/04/2025

CVE-2025-1770 Élevée · 8,8
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 – Authenticated (Contributor+) Local File Inclusion

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.24 via the 'style' parameter. This makes it possible for authenticated attackers, with…

Versions affectées

*-4.0.24

Correctif

4.0.25

Publication

19/03/2025

CVE-2025-1766 Moyenne · 5,3
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 – Missing Authorization to Unauthenticated Payment Status Update

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'payment_complete' function in all versions up to, and including, 4.0.24. This…

Versions affectées

*-4.0.24

Correctif

4.0.25

Publication

19/03/2025

CVE-2025-26964 Élevée · 8,8
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

Eventin <= 4.0.20 – Authenticated (Contributor+) Local File Inclusion

The Eventin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.20. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the…

Versions affectées

*-4.0.20

Correctif

4.0.21

Publication

23/02/2025

CVE-2024-56213 Élevée · 8,8
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

Eventin <= 4.0.7 – Authenticated (Contributor+) Local File Inclusion

The Eventin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.7. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the…

Versions affectées

*-4.0.7

Correctif

4.0.9

Publication

19/12/2024

CVE-2024-7149 Élevée · 8,8
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.8 – Authenticated (Contributor+) Local File Inclusion

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.8 via multiple style parameters. This makes it possible for authenticated attackers, with…

Versions affectées

*-4.0.8

Correctif

4.0.9

Publication

26/09/2024

CVE-2024-39648 Moyenne · 6,4
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

Eventin <= 4.0.5 – Authenticated (Author+) Stored Cross-Site Scripting

The Eventin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above,…

Versions affectées

*-4.0.5

Correctif

4.0.6

Publication

01/08/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités