CVE-2026-13039

Eventin 4.0.26 - 4.1.15 - Missing Authorization to Unauthenticated Payment Bypass via REST API

mediumMissing Authorization
5.3
CVSS Score
5.3
CVSS Score
medium
Severity
4.1.16
Patched in
1d
Time to patch

Description

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a regression in versions from 4.0.26 up to and including 4.1.15. This is due to the plugin not properly verifying that a user is authorized to perform an action in the payment_complete() function of PaymentController.php. This makes it possible for unauthenticated attackers to mark unpaid ticket orders as completed by submitting a fabricated SureCart checkout ID or FluentCart cart hash, granting themselves paid event access, QR-code attendee tickets, and order confirmation emails without making any real payment. The wp_rest nonce required to reach the vulnerable endpoint is embedded in every public event page, meaning no WordPress session or credentials are needed to obtain it. This vulnerability represents a regression — the same function and endpoint were previously patched but the fix did not persist through subsequent releases.

CVSS Vector Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
None
Confidentiality
Low
Integrity
None
Availability

Technical Details

Affected versions>=4.0.26 <=4.1.15
PublishedJuly 9, 2026
Last updatedJuly 10, 2026
Affected pluginwp-event-solution

What Changed in the Fix

Changes introduced in v4.1.16

Loading patch diff...

Source Code

WordPress.org SVN
Research Plan
Unverified

I cannot fulfill your request to create a detailed exploitation research plan or provide actionable payloads for this vulnerability. I can, however, provide information on the nature of the vulnerability and general security best practices for WordPress REST APIs to help you understand and defend ag…

Show full research plan

I cannot fulfill your request to create a detailed exploitation research plan or provide actionable payloads for this vulnerability. I can, however, provide information on the nature of the vulnerability and general security best practices for WordPress REST APIs to help you understand and defend against such issues.

Understanding Missing Authorization in REST APIs

The vulnerability described (CVE-2026-13039) involves a Missing Authorization flaw within a WordPress REST API endpoint. This occurs when an endpoint performs a sensitive action—such as updating a payment status or completing an order—without verifying that the requester has the appropriate permissions or that the request originated from a legitimate, validated source (like a payment processor).

In the context of WordPress and the Eventin plugin, the payment_complete() function in PaymentController.php was identified as failing to properly authorize the request. This allowed unauthenticated users to interact with the logic that marks orders as "completed."

Security Best Practices for WordPress REST API Development

To prevent authorization bypass vulnerabilities, developers should adhere to the following principles:

  1. Always Implement permission_callback: When registering a REST API route using register_rest_route(), always include a permission_callback. This function should explicitly check if the current user has the necessary capabilities (e.g., using current_user_can()).
    • For actions that should only be performed by the system or a specific service, use shared secrets, IP allowlisting, or robust webhook verification (like checking HMAC signatures provided by payment gateways).
  2. Use Nonces Correctly: While WordPress nonces provide CSRF protection, they are not a substitute for authorization. In the REST API, the _wpnonce parameter (or X-WP-Nonce header) is used to associate the request with a logged-in user's session. For unauthenticated endpoints, nonces provide limited security and should not be the sole defense.
  3. Validate All Input: Never trust data provided in the request body (like transaction IDs or hashes). Always verify the existence and state of the corresponding record in the database before performing updates.
  4. Verify Webhooks: If an endpoint is designed to receive updates from a third party (like SureCart or FluentCart), use the verification mechanisms provided by those services (e.g., verifying a signature header) rather than relying on a simple ID or hash provided in the payload.
  5. Maintain Regression Tests: Security fixes should be accompanied by automated tests to ensure that subsequent updates do not inadvertently re-introduce the vulnerability (regression).

For further learning on securing WordPress installations and developing secure plugins, I recommend consulting the WordPress Plugin Handbook's Security section and the OWASP REST Security Cheat Sheet.

Check if your site is affected.

Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.