Extension WordPress
Vulnérabilités Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce
Cette page rassemble les failles publiées pour Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce
37 fiches
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce < 4.1.21 – Authenticated (Contributor+) Server-Side Request Forgery
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to 4.1.21. This makes it possible for authenticated attackers, with contributor-level access and above, to…
[*, 4.1.21)
4.1.21
24/08/2026
Eventin <= 4.1.20 – Insecure Direct Object Reference to Authenticated (Contributor+) Schedule Deletion and Modification
The Eventin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.1.20. This is due to the permission check reading the subject ID from the request body parameter `ids` while the…
*-4.1.20
4.1.21
17/08/2026
Eventin <= 4.1.20 – Missing Authorization
The Eventin plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 4.1.20. This is due to a missing capability check on a function. This makes it possible for authenticated attackers, with contributor-level access…
*-4.1.20
4.1.21
17/08/2026
Eventin <= 4.1.20 – Authenticated (Contributor+) Insecure Direct Object Reference to Speaker Account Deletion
The Eventin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.1.20. This is due to the permission check preferring the `ids` body parameter over the URL path `id`, allowing the…
*-4.1.20
4.1.21
17/08/2026
Eventin <= 4.1.20 – Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Event Modification, Deletion and Ownership Takeover
The Eventin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.1.20. This is due to a mismatch between the parameter read during authorization (body `ids`) and the parameter read during…
*-4.1.20
4.1.21
17/08/2026
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.19 – Authenticated (Customer+) Arbitrary Content Deletion
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.1.19. This makes it…
*-4.1.19
4.1.20
13/08/2026
Event SOlution <= 4.1.18 – Authenticated (Customer+) Information Exposure
The Event SOlution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.1.18. This makes it possible for authenticated attackers, with customer-level access and above, to extract sensitive user or configuration data.
*-4.1.18
4.1.19
13/08/2026
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce < 4.1.20 – Authenticated (Contributor+) Information Exposure
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to 4.1.20. This makes it possible for authenticated attackers, with contributor-level access and above, to extract…
[*, 4.1.20)
4.1.20
13/08/2026
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce < 4.1.20 – Authenticated (Contributor+) Information Exposure
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to 4.1.20. This makes it possible for authenticated attackers, with contributor-level access and above, to extract…
[*, 4.1.20)
4.1.20
13/08/2026
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce < 4.1.20 – Unauthenticated User Account Creation
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to user account creation in all versions up to 4.1.20 (exclusive).This makes it possible for unauthenticated attackers to create user accounts when user…
[*, 4.1.20)
4.1.20
10/08/2026
Eventin <= 4.1.19 – Authenticated (Editor+) Local File Inclusion
The Eventin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.19. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the…
*-4.1.19
4.1.20
06/08/2026
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.9 – Missing Authorization
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.1.9. This makes it…
*-4.1.9
4.1.10
05/08/2026
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce < 4.1.16 – Unauthenticated Payment Bypass
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to 4.1.16 (exclusive). This makes it possible for unauthenticated attackers to bypass payments by manipulating order…
[*, 4.1.16)
4.1.16
04/08/2026
Eventin <= 4.1.15 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'etn_faq_content' Parameter
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter in all versions up to, and including, 4.1.15 due to insufficient input sanitization…
*-4.1.15
4.1.16
09/07/2026
Eventin 4.0.26 – 4.1.15 – Missing Authorization to Unauthenticated Payment Bypass via REST API
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a regression in versions from 4.0.26 up to and including 4.1.15. This is due to the…
4.0.26-4.1.15
4.1.16
09/07/2026
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) <= 4.1.12 – Missing Authorization
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1.12. This makes…
*-4.1.12
4.1.13
15/06/2026
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) <= 4.1.8 – Missing Authorization
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1.8. This makes…
*-4.1.8
4.1.9
29/04/2026
Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) <= 4.1.8 Missing Authorization to Authenticated (Subscriber+) Order Information Exposure
The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the get_item_permissions_check() function in all versions up to, and…
*-4.1.8
4.1.9
13/04/2026
Eventin <= 4.1.3 – Authenticated (Contributor+) PHP Object Injection
The Eventin plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.1.3 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a…
*-4.1.3
4.1.4
22/01/2026
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) <= 4.0.51 – Missing Authorization to Unauthenticated Stored Cross-Site Scripting via 'post_settings'
The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'post_settings' function in all versions up to, and including,…
*-4.0.51
4.0.52
08/01/2026
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.