CVE-2026-40776 is an unauthenticated broken access control vulnerability affecting WP Event SOlution versions up to and including 4.1.8. The available information indicates that the plugin fails to properly enforce authorization checks on functionality or data that should be restricted, allowing requests from an unauthenticated actor to bypass intended access controls. Specific vulnerable endpoints, functions, or code paths are not provided in the available content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a small, focused exploit/advisory package for CVE-2026-40776 affecting the WordPress Eventin plugin (wp-event-solution) <= 4.1.8. It contains 4 files total: two documentation files (README.md and ADVISORY.md), a license, and one executable PoC script at poc/poc-eventin.sh. The advisory explains that the plugin exposes a public REST endpoint, /wp-json/eventin/v1/nonce, which returns a valid wp_rest nonce to unauthenticated users. Multiple downstream REST permission callbacks then incorrectly treat possession of that nonce as authorization, and one order-read path lacks ownership checks, producing an unauthenticated IDOR. The included Bash PoC is operational rather than just descriptive: it fetches the nonce, uses it in the X-Wp-Nonce header to read order ID 21, demonstrates that the same request without the nonce fails, and then submits a forged order with attacker-controlled customer and attendee fields to /wp-json/eventin/v2/orders. The documentation also identifies additional exploit capability not directly exercised in the script: interaction with vulnerable payment endpoints and abuse of /wp-json/eventin/v2/orders/book-seats, whose permission callback is fully open, enabling seat exhaustion/booking DoS. Overall, the repository’s purpose is to document and reproduce a real broken access control flaw leading to unauthenticated PII disclosure, arbitrary order creation, and related abuse of Eventin REST endpoints.
This repository is a small, focused exploit/advisory package for CVE-2026-40776 affecting the Themewinter Eventin WordPress plugin (wp-event-solution) <= 4.1.8. It contains three documentation files (README.md, ADVISORY.md, LICENSE) and one executable PoC script (poc/poc-eventin.sh). The advisory explains that the plugin exposes a public REST endpoint that returns a valid wp_rest nonce to unauthenticated users, and downstream REST permission callbacks incorrectly treat that nonce as authorization. Combined with missing ownership checks on order retrieval and an open seat-booking route, this enables unauthenticated access to sensitive order data, forged order creation, payment endpoint interaction, and booking abuse. The main exploit logic is in poc/poc-eventin.sh. The script performs a 4-step attack chain against a local lab target: (1) GET /wp-json/eventin/v1/nonce to obtain a nonce without authentication, (2) use X-Wp-Nonce to read a specific order via /wp-json/eventin/v2/orders/21, demonstrating IDOR and PII exposure, (3) repeat the same request without the nonce to show the access control difference, and (4) POST attacker-controlled JSON to /wp-json/eventin/v2/orders to create a fake order. The payload is hardcoded and basic, so the exploit is operational rather than heavily weaponized. Overall purpose: document and reproduce a real broken access control flaw in a WordPress plugin. Main capabilities demonstrated by code are unauthorized nonce acquisition, unauthorized order read, and unauthorized order creation. Additional vulnerable routes and behaviors, including /wp-json/eventin/v2/payments and /wp-json/eventin/v2/orders/book-seats, are described in the advisory/README but not directly exercised in the PoC script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.