haitam lazaar / lazaarsec
← Back to CVE Registry
CVE-2026-13178unrated[patched]

Unauthenticated Payment Bypass via Order Status Manipulation

TARGET ECOSYSTEM / VENDORThemewinter
AFFECTED PRODUCTEventin (< 4.1.16)
CWE CLASSIFICATIONCWE-639: Insecure Direct Object Reference
PUBLISHED DATE2026-07-13

Summary

Eventin (< 4.1.16) does not properly authorize order creation and accepts an attacker-supplied order status. This allows unauthenticated users to create event ticket orders and manually mark them as paid/completed without completing any payment process.

Official Status

  • CNA Rating: Unrated
  • Impact: Unauthenticated Payment Bypass
  • Fixed Version: 4.1.16