CVE-2026-13178
HIGHEventin < 4.1.16 - Unauthenticated Payment Bypass via Order Status Manipulation
Title source: cnaDescription
The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment.
References (1)
Core 1
Core References
Exploit exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/09d6135f-b38c-4cfe-8a9f-5d79552c720c/
Scores
CVSS v3
7.5
EPSS
0.0015
EPSS Percentile
4.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (1)
None/Eventin
< 4.1.16
Published
Jul 30, 2026
Tracked Since
Jul 30, 2026