CVE-2026-77694

Eventin < 4.1.19 - Unauthenticated Order Completion Without Payment via order_token

The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed to authorise on an order, allowing unauthenticated users to mark their own unpaid order as completed and be issued a valid paid ticket with no payment taken.


We have discovered 2,388 live websites that are affected by CVE-2026-77694.

Run a Free Instant Scan




Affected Software

Product  Wp Event Solution
Category Wordpress Plugins
Vulnerable Domains2,388 live websites (100% of Wp Event Solution install base)
Vulnerable Versions
  • from 0 through 4.1.19
Vulnerable Versions Count119 versions ( 99% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Aug 26, 2026
  • Updated - Aug 26, 2026

Credits

  • Nir Yehoshua (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-77694
United States806 websites



Germany176 websites
Switzerland155 websites
GB116 websites
France110 websites
Canada94 websites
Netherlands94 websites
Italy62 websites
India61 websites
Cyprus53 websites

Website Distribution by TLD

Number of websites using CVE-2026-77694
.com758 websites
.org473 websites
.ch146 websites
.de79 websites
.nl68 websites
.ca56 websites
.it47 websites
.co.uk40 websites
.com.br38 websites
.net35 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-77694

Top websites that are affected by CVE-2026-77694. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com Thailand***,***
**********.org United States***,***
****.pe Peru***,***
***********.org Germany***,***
******.org United States***,***
******.com Indonesia***,***
**********************.org United States***,***
******.**.id Indonesia***,***
****.de United States***,***
****.es United States***,***
See full domain list

FAQ

CVE-2026-77694 is Missing Authorization in Wp Event Solution
A total of 2,388 websites have been identified as vulnerable to CVE-2026-77694, based on global website indexing conducted by WebTechSurvey.
The Wp Event Solution is affected by the CVE-2026-77694 vulnerability.
Wp Event Solution versions up to 4.1.19 are vulnerable to CVE-2026-77694.
CVE-2026-77694 is resolved in version 4.1.19 of Wp Event Solution.