CVE-2026-12956
Last modified
CVE-2026-12956 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The WP Event Solution (Eventin) plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 4.1.22 via the create_item() handler for the /wp-json/eventin/v2/orders REST endpoint. The endpoint's create_item_permissions_check() function only verifies a wp_rest nonce (which is leaked to every visitor through the etn-public script's localized_data_obj on every frontend page) and accepts a user-supplied 'status' value in prepare_item_for_database() with no whitelist validation. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
The WP Event Solution (Eventin) plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 4.1.22 via the create_item() handler for the /wp-json/eventin/v2/orders REST endpoint. The endpoint's create_item_permissions_check() function only verifies a wp_rest nonce (which is leaked to every visitor through the etn-public script's localized_data_obj on every frontend page) and accepts a user-supplied 'status' value in prepare_item_for_database() with no whitelist validation. This makes it possible for unauthenticated attackers to create etn-order posts with status='completed' that are counted as sold by etn_get_sold_tickets_by_event(); because the auto-cleanup wp_schedule_single_event() in create_item() only fires for status='pending' orders, the forged completed orders persist indefinitely and exhaust ticket inventory.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| arraytics | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce | <= 4.1.22 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-12956?
How severe is CVE-2026-12956?
How do I fix CVE-2026-12956?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-12947IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12…7.5
- CVE-2026-12948A stored cross-site scripting (XSS) vulnerability in the web…4.8
- CVE-2026-12949The Wishlist Member plugin for WordPress is vulnerable to Ac…9.8
- CVE-2026-1295The Buy Now Plus – Buy Now buttons for Stripe plugin for Wor…6.4
- CVE-2026-12954The Mapster WP Maps plugin for WordPress is vulnerable to Ar…8.8
- CVE-2026-12955The GDPR Cookie Consent plugin for WordPress is vulnerable t…4.3
- CVE-2026-12957Improper trust boundary enforcement in Language Servers for …8.5
- CVE-2026-12958Missing symlink validation in Language Servers for AWS may a…8.5
- CVE-2026-1296The Frontend Post Submission Manager Lite plugin for WordPre…6.1
- CVE-2026-12960An Improper Export of Android Application Components vulnera…6
- CVE-2026-12962A Permissive Cross-domain Security Policy with Untrusted Dom…5.3
- CVE-2026-12965The Super Store Finder WordPress plugin before 7.11 does not…9.1
Are you affected by CVE-2026-12956?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
