CVE-2026-13178

Eventin < 4.1.16 - Unauthenticated Payment Bypass via Order Status Manipulation

The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment.


We have discovered 2,411 live websites that are affected by CVE-2026-13178.

Run a Free Instant Scan




Affected Software

Product  Wp Event Solution
Category Wordpress Plugins
Vulnerable Domains2,411 live websites (100% of Wp Event Solution install base)
Vulnerable Versions
  • from 0 through 4.1.16
Vulnerable Versions Count117 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-639 Authorization Bypass Through User-Controlled Key



Details

  • Published - Jul 30, 2026
  • Updated - Jul 30, 2026

Credits

  • Haitam Lazaar (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-13178
United States807 websites



Germany172 websites
Switzerland157 websites
GB118 websites
France105 websites
Netherlands95 websites
Canada91 websites
India67 websites
Italy63 websites
Cyprus58 websites

Website Distribution by TLD

Number of websites using CVE-2026-13178
.com760 websites
.org471 websites
.ch147 websites
.de84 websites
.nl70 websites
.ca57 websites
.it47 websites
.co.uk42 websites
.com.br39 websites
.net33 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-13178

Top websites that are affected by CVE-2026-13178. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****************.be Belgium**,***
*******.com Thailand***,***
**********.org United States***,***
***********.com United States***,***
****.pe Peru***,***
***********.org Germany***,***
******.org United States***,***
******.com Indonesia***,***
**********************.org United States***,***
******.**.id Indonesia***,***
See full domain list

FAQ

CVE-2026-13178 is Authorization Bypass Through User-Controlled Key in Wp Event Solution
A total of 2,411 websites have been identified as vulnerable to CVE-2026-13178, based on global website indexing conducted by WebTechSurvey.
The Wp Event Solution is affected by the CVE-2026-13178 vulnerability.
Wp Event Solution versions up to 4.1.16 are vulnerable to CVE-2026-13178.
CVE-2026-13178 is resolved in version 4.1.16 of Wp Event Solution.