WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce

Event calendar plugin for event registration, event tickets, bookings, RSVP, recurring and virtual events with WooCommerce and Zoom (AI-powered).

38Reported vulnerabilities
9.8Highest CVSS score
4.1.21Latest version
10,000+Active installs

What to do now

Update Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce to 4.1.22 or later. 38 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 12, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2025-47539 Critical 9.8 27.9% 4.0.26 and earlier 4.0.27 May 7, 2025
CVE-2025-39584 High 8.8 0.9% 4.0.25 and earlier 4.0.26 April 16, 2025
CVE-2025-1770 High 8.8 0.9% Before 4.0.25 4.0.25 March 20, 2025
CVE-2024-7149 High 8.8 1.0% Before 4.0.9 4.0.9 September 27, 2024
CVE-2025-4796 High 8.8 0.6% Before 4.0.35 4.0.35 August 8, 2025
CVE-2025-26964 High 8.8 0.7% 4.0.20 and earlier 4.0.21 February 23, 2025
CVE-2024-56213 High 8.8 0.6% 4.0.7 and earlier 4.0.9 December 19, 2024
CVE-2025-3419 High 7.5 0.7% Before 4.0.27 4.0.27 May 8, 2025
CVE-2025-68047 High 7.5 0.5% 4.1.3 and earlier 4.1.4 January 22, 2026
CVE-2025-49869 High 7.5 0.4% 4.0.31 and earlier 4.0.32 August 13, 2025
CVE-2025-14657 High 7.2 0.3% 0 to 4.0.51 (inclusive) 4.0.52 January 9, 2026
CVE-2025-7813 High 7.2 0.3% 0 to 4.0.37 (inclusive) 4.0.38 August 23, 2025
CVE-2026-13170 Medium 6.6 0.4% 4.1.19 and earlier 4.1.20 August 6, 2026
CVE-2026-12924 Medium 6.4 0.4% 0 to 4.1.15 (inclusive) 4.1.16 July 10, 2026
CVE-2024-39648 Medium 6.4 0.3% 4.0.5 and earlier 4.0.6 August 1, 2024
CVE-2024-37507 Medium 6.4 0.3% 3.3.57 and earlier 4.0.0 July 4, 2024
CVE-2026-13175 Medium 6.3 0.3% 4.1.20 and earlier 4.1.21 August 17, 2026
CVE-2025-49321 Medium 6.1 0.2% 4.0.28 and earlier 4.0.29 June 23, 2025
CVE-2026-13172 Medium 5.3 0.3% Before 4.1.22 4.1.22 August 26, 2026
CVE-2026-77694 Medium 5.3 0.2% Before 4.1.19 4.1.19 August 24, 2026
CVE-2026-13171 Medium 5.3 0.2% Before 4.1.20 4.1.20 August 10, 2026
CVE-2026-66451 Medium 5.3 0.2% 4.1.9 and earlier 4.1.10 August 5, 2026
CVE-2026-13178 Medium 5.3 0.3% Before 4.1.16 4.1.16 August 4, 2026
CVE-2026-13039 Medium 5.3 0.4% 4.0.26 to 4.1.15 (inclusive) 4.1.16 July 9, 2026
CVE-2025-68045 Medium 5.3 0.2% 4.1.12 and earlier 4.1.13 June 15, 2026
CVE-2026-40776 Medium 5.3 0.4% 4.1.8 and earlier 4.1.9 April 29, 2026
CVE-2025-1766 Medium 5.3 0.4% Before 4.0.25 4.0.25 March 20, 2025
CVE-2024-1122 Medium 5.3 0.5% Before 3.3.51 3.3.51 February 9, 2024
CVE-2026-13169 Medium 4.3 0.2% 4.1.20 and earlier 4.1.21 August 17, 2026
CVE-2026-13173 Medium 4.3 0.2% 4.1.20 and earlier 4.1.21 August 17, 2026
CVE-2026-13174 Medium 4.3 0.3% 4.1.20 and earlier 4.1.21 August 17, 2026
CVE-2026-28174 Medium 4.3 0.3% 4.1.18 and earlier 4.1.19 August 13, 2026
CVE-2026-13168 Medium 4.3 0.3% Before 4.1.20 4.1.20 August 13, 2026
CVE-2026-13177 Medium 4.3 0.2% Before 4.1.20 4.1.20 August 13, 2026
CVE-2026-28173 Medium 4.3 0.2% 4.1.19 and earlier 4.1.20 August 13, 2026
CVE-2026-4109 Medium 4.3 0.2% 4.1.8 and earlier 4.1.9 April 13, 2026
CVE-2024-6033 Medium 4.3 0.4% Before 4.0.5 4.0.5 July 17, 2024
CVE-2026-13176 Low 2.7 0.2% 0 up to (but not including) 4.1.21 4.1.21 August 21, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.