← Back to CVE Registry
CVE-2026-13178unrated[patched]
Unauthenticated Payment Bypass via Order Status Manipulation
TARGET ECOSYSTEM / VENDORThemewinter
AFFECTED PRODUCTEventin (< 4.1.16)
CWE CLASSIFICATIONCWE-639: Insecure Direct Object Reference
PUBLISHED DATE2026-07-13
ADVISORY / CNAWPScan Advisory (CNA) ↗
Summary
Eventin (< 4.1.16) does not properly authorize order creation and accepts an attacker-supplied order status. This allows unauthenticated users to create event ticket orders and manually mark them as paid/completed without completing any payment process.
Official Status
- CNA Rating: Unrated
- Impact: Unauthenticated Payment Bypass
- Fixed Version: 4.1.16