The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed to authorise on an order, allowing unauthenticated users to mark their own unpaid order as completed and be issued a valid paid ticket with no payment taken.
We have discovered 2,388 live websites that are affected by CVE-2026-77694.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 2,388 live websites (100% of Wp Event Solution install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 119 versions ( 99% of all versions) |
| 806 websites | |
| 176 websites | |
| 155 websites | |
| 116 websites | |
| 110 websites | |
| 94 websites | |
| 94 websites | |
| 62 websites | |
| 61 websites | |
| 53 websites |
| .com | 758 websites |
| .org | 473 websites |
| .ch | 146 websites |
| .de | 79 websites |
| .nl | 68 websites |
| .ca | 56 websites |
| .it | 47 websites |
| .co.uk | 40 websites |
| .com.br | 38 websites |
| .net | 35 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | ***,*** | ||
| **********.org | ***,*** | ||
| ****.pe | ***,*** | ||
| ***********.org | ***,*** | ||
| ******.org | ***,*** | ||
| ******.com | ***,*** | ||
| **********************.org | ***,*** | ||
| ******.**.id | ***,*** | ||
| ****.de | ***,*** | ||
| ****.es | ***,*** |
FAQ