CVE-2026-84906

MEDIUM Status: Received

CVSS Scores

CVSS v3.x Base Score
5.3
MEDIUM

Description

The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its amount, currency, or which order it belongs to, allowing unauthenticated visitors to mark unpaid orders of any value as paid by replaying the transaction of a single genuine low-value payment.

Published
September 16, 2026 7:16 AM
Last Modified
September 16, 2026 7:16 AM
Source
[email protected]

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.