Extension WordPress
Vulnérabilités Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)
Cette page rassemble les failles publiées pour Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)
24 fiches
Eventin <= 4.1.15 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'etn_faq_content' Parameter
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter in all versions up to, and including, 4.1.15 due to insufficient input sanitization…
*-4.1.15
4.1.16
09/07/2026
Eventin 4.0.26 – 4.1.15 – Missing Authorization to Unauthenticated Payment Bypass via REST API
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a regression in versions from 4.0.26 up to and including 4.1.15. This is due to the…
4.0.26-4.1.15
4.1.16
09/07/2026
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) <= 4.1.12 – Missing Authorization
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1.12. This makes…
*-4.1.12
4.1.13
15/06/2026
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) <= 4.1.8 – Missing Authorization
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1.8. This makes…
*-4.1.8
4.1.9
29/04/2026
Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) <= 4.1.8 Missing Authorization to Authenticated (Subscriber+) Order Information Exposure
The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the get_item_permissions_check() function in all versions up to, and…
*-4.1.8
4.1.9
13/04/2026
Eventin <= 4.1.3 – Authenticated (Contributor+) PHP Object Injection
The Eventin plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.1.3 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a…
*-4.1.3
4.1.4
22/01/2026
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) <= 4.0.51 – Missing Authorization to Unauthenticated Stored Cross-Site Scripting via 'post_settings'
The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'post_settings' function in all versions up to, and including,…
*-4.0.51
4.0.52
08/01/2026
Event Manager, Events Calendar, Booking, Registrations and Tickets – Eventin <= 4.0.37 – Unauthenticated Server-Side Request Forgery
The Events Calendar, Event Booking, Registrations and Event Tickets – Eventin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.37 via the proxy_image function. This makes it possible for unauthenticated…
*-4.0.37
4.0.38
22/08/2025
Eventin <= 4.0.31 – Authenticated (Contributor+) PHP Object Injection
The Eventin plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.0.31 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a…
*-4.0.31
4.0.32
13/08/2025
Eventin <= 4.0.34 – Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover
The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due to the plugin not properly validating a user's identity or capability prior to updating…
*-4.0.34
4.0.35
08/08/2025
Eventin <= 4.0.28 – Reflected Cross-Site Scripting
The Event Manager, Events Calendar, Booking, Registrations and Tickets – Eventin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.0.28 due to insufficient input sanitization and output escaping. This makes…
*-4.0.28
4.0.29
23/06/2025
Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.26 – Unauthenticated Arbitrary File Read
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 4.0.26 via the proxy_image() function. This makes it possible for unauthenticated attackers to…
*-4.0.26
4.0.27
07/05/2025
Eventin <= 4.0.26 – Missing Authorization to Unauthenticated Privilege Escalation
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the import_items() function in all versions up to, and including, 4.0.26. This makes it…
*-4.0.26
4.0.27
07/05/2025
Eventin <= 4.0.25 – Authenticated (Contributor+) Local File Inclusion
The Eventin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.25 via the 'events_tab' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute…
*-4.0.25
4.0.26
16/04/2025
Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 – Authenticated (Contributor+) Local File Inclusion
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.24 via the 'style' parameter. This makes it possible for authenticated attackers, with…
*-4.0.24
4.0.25
19/03/2025
Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 – Missing Authorization to Unauthenticated Payment Status Update
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'payment_complete' function in all versions up to, and including, 4.0.24. This…
*-4.0.24
4.0.25
19/03/2025
Eventin <= 4.0.20 – Authenticated (Contributor+) Local File Inclusion
The Eventin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.20. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the…
*-4.0.20
4.0.21
23/02/2025
Eventin <= 4.0.7 – Authenticated (Contributor+) Local File Inclusion
The Eventin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.7. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the…
*-4.0.7
4.0.9
19/12/2024
Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.8 – Authenticated (Contributor+) Local File Inclusion
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.8 via multiple style parameters. This makes it possible for authenticated attackers, with…
*-4.0.8
4.0.9
26/09/2024
Eventin <= 4.0.5 – Authenticated (Author+) Stored Cross-Site Scripting
The Eventin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above,…
*-4.0.5
4.0.6
01/08/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.