PT-2026-32605 · WordPress · Eventin

Supakiad S

·

Published

2026-04-14

·

Updated

2026-04-14

·

CVE-2026-4109

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) versions prior to 4.1.9
Description An improper capability check in the get item permissions check() function allows authenticated attackers with Subscriber-level access or higher to gain unauthorized access to data. By iterating order IDs, an attacker can read arbitrary order information, including customer personally identifiable information (PII) such as name, email, and phone number.
Recommendations Update to a version newer than 4.1.8.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-4109

Affected Products

Eventin