What is CVE-2026-13168?
The Eventin WordPress plugin before version 4.1.20 fails to properly restrict access to stored customer records. This allows users with contributor-level access and above to read other customers' personal data, such as names and email addresses. Updating the plugin to the latest version is strongly recommended.
Azərbaycanca: Eventin WordPress plaqini 4.1.20 versiyasından əvvəl müştəri qeydlərinə girişi məhdudlaşdırmır. Bu, Contributor və daha yuxarı səviyyəli istifadəçilərə başqa müştərilərin ad və email kimi şəxsi məlumatlarını oxumağa imkan verir. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What user level is affected by the CVE-2026-13168 vulnerability in the Eventin WordPress plugin?
The vulnerability affects users with contributor-level access and above, allowing them to read other customers' personal data such as names and email addresses.
To which version should the Eventin plugin be updated to protect against CVE-2026-13168?
Versions before 4.1.20 are vulnerable, so updating to at least version 4.1.20 or higher is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.