The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment.
We have discovered 2,411 live websites that are affected by CVE-2026-13178.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 2,411 live websites (100% of Wp Event Solution install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 117 versions ( 100% of all versions) |
| 807 websites | |
| 172 websites | |
| 157 websites | |
| 118 websites | |
| 105 websites | |
| 95 websites | |
| 91 websites | |
| 67 websites | |
| 63 websites | |
| 58 websites |
| .com | 760 websites |
| .org | 471 websites |
| .ch | 147 websites |
| .de | 84 websites |
| .nl | 70 websites |
| .ca | 57 websites |
| .it | 47 websites |
| .co.uk | 42 websites |
| .com.br | 39 websites |
| .net | 33 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****************.be | **,*** | ||
| *******.com | ***,*** | ||
| **********.org | ***,*** | ||
| ***********.com | ***,*** | ||
| ****.pe | ***,*** | ||
| ***********.org | ***,*** | ||
| ******.org | ***,*** | ||
| ******.com | ***,*** | ||
| **********************.org | ***,*** | ||
| ******.**.id | ***,*** |
FAQ