The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a regression in versions from 4.0.26 up to and including 4.1.15. This regression affects the payment_complete() function in PaymentController.php, allowing unauthenticated attackers to manipulate ticket orders. The vulnerability has a CVSS score of 5.3 and is c [truncated]
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter in all versions up to, and including, 4.1.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scr [truncated]
The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to list, create, update, delete, clone, [truncated]
CVE-2025-68045 is a HIGH severity vulnerability in the WP Event Solution plugin for WordPress. The vulnerability has a CVSS score of 7.5 and is categorized as Unauthenticated Broken Access Control. It affects plugin versions <= 4.1.12.
CVE-2026-40776 is a HIGH severity vulnerability in WP Event SOlution plugin versions <= 4.1.8. The vulnerability has a CVSS score of 7.5 and is categorized as Unauthenticated Broken Access Control. It was published on [cvePublishedAt] and last modified on [cveModifiedAt].