PatchSiren

Arraytics CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Arraytics CVE published 2026-09-11

CVE-2026-62135

CVE-2026-62135 is a MEDIUM severity vulnerability in Booktics plugin versions <= 1.0.24. It allows unauthenticated broken access control. Defenders should assess exposure, prioritize remediation, and verify inventory.

MEDIUM arraytics CVE published 2026-09-11

CVE-2026-11446

The Booktics – Booking Calendar for Appointments and Service Businesses plugin for WordPress is vulnerable to unauthorized modification of data. A vulnerability exists in all versions up to, and including, 1.0.23 due to the create_order_permission() permission callback on the POST /wp-json/booktics/v1/orders REST route unconditionally returning true. This, combined with find_and_update_guest() overwriting [truncated]

MEDIUM Arraytics CVE published 2026-08-06

CVE-2026-66451

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:20.340Z and has not been modified since then. This unauthenticated broken authentication vulnerability in WP Event Solution plugin versions <= 4.1.9 has a CVSS score of 6.5 and is classified as MEDIUM severity. Users of WP Event Solution plugin versions <= 4.1.9 should verify and apply patc [truncated]

MEDIUM arraytics CVE published 2026-07-10

CVE-2026-13039

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a regression in versions from 4.0.26 up to and including 4.1.15. This regression affects the payment_complete() function in PaymentController.php, allowing unauthenticated attackers to manipulate ticket orders. The vulnerability has a CVSS score of 5.3 and is c [truncated]

MEDIUM arraytics CVE published 2026-07-10

CVE-2026-12924

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter in all versions up to, and including, 4.1.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scr [truncated]

MEDIUM arraytics CVE published 2026-07-10

CVE-2026-11818

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to list, create, update, delete, clone, [truncated]

HIGH Arraytics CVE published 2026-06-16

CVE-2025-68045

CVE-2025-68045 is a HIGH severity vulnerability in the WP Event Solution plugin for WordPress. The vulnerability has a CVSS score of 7.5 and is categorized as Unauthenticated Broken Access Control. It affects plugin versions <= 4.1.12.

HIGH Arraytics CVE published 2026-06-15

CVE-2026-40776

CVE-2026-40776 is a HIGH severity vulnerability in WP Event SOlution plugin versions <= 4.1.8. The vulnerability has a CVSS score of 7.5 and is categorized as Unauthenticated Broken Access Control. It was published on [cvePublishedAt] and last modified on [cveModifiedAt].