What is CVE-2026-13178?
The Eventin WordPress plugin before version 4.1.16 contains an authorization flaw that allows unauthenticated users to create orders with a 'paid' status without completing any payment. It is strongly recommended to update the plugin to the latest version immediately.
Azərbaycanca: Eventin WordPress plugin-inin 4.1.16-dən əvvəlki versiyalarında avtorizasiya zəifliyi mövcuddur. Bu, autentifikasiya olunmamış istifadəçilərə heç bir ödəniş etmədən 'paid' statuslu saxta sifarişlər yaratmağa imkan verir. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Eventin WordPress plugin are affected by CVE-2026-13178?
CVE-2026-13178 affects versions of the Eventin WordPress plugin prior to 4.1.16. Updating the plugin to the latest version mitigates this issue.
What does CVE-2026-13178 allow unauthenticated users to do?
This vulnerability allows unauthenticated users to create orders with a 'paid' status without completing any payment.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.