PatchSiren

Arraytics CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM arraytics CVE published 2026-07-10

CVE-2026-13039

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a regression in versions from 4.0.26 up to and including 4.1.15. This regression affects the payment_complete() function in PaymentController.php, allowing unauthenticated attackers to manipulate ticket orders. The vulnerability has a CVSS score of 5.3 and is c [truncated]

MEDIUM arraytics CVE published 2026-07-10

CVE-2026-12924

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter in all versions up to, and including, 4.1.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scr [truncated]

MEDIUM arraytics CVE published 2026-07-10

CVE-2026-11818

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to list, create, update, delete, clone, [truncated]

HIGH Arraytics CVE published 2026-06-16

CVE-2025-68045

CVE-2025-68045 is a HIGH severity vulnerability in the WP Event Solution plugin for WordPress. The vulnerability has a CVSS score of 7.5 and is categorized as Unauthenticated Broken Access Control. It affects plugin versions <= 4.1.12.

HIGH Arraytics CVE published 2026-06-15

CVE-2026-40776

CVE-2026-40776 is a HIGH severity vulnerability in WP Event SOlution plugin versions <= 4.1.8. The vulnerability has a CVSS score of 7.5 and is categorized as Unauthenticated Broken Access Control. It was published on [cvePublishedAt] and last modified on [cveModifiedAt].