What is CVE-2026-13169?
CVE-2026-13169 is a vulnerability in the Eventin WordPress plugin before version 4.1.21 where event ownership is not properly verified. This allows users with contributor-level access and above to modify, delete, or reassign events created by other users, including admins. Immediate update to version 4.1.21 or later is recommended.
Azərbaycanca: CVE-2026-13169, WordPress-in Eventin plugin-inin 4.1.21-dən əvvəlki versiyalarında, hadisə sahibliyinin düzgün yoxlanılmaması zəifliyidir. Bu, contributor və daha yuxarı səviyyəli istifadəçilərə başqa istifadəçilərin yaratdığı hadisələri dəyişdirmək, silmək və ya başqa müəllifə təhvil vermək imkanı yaradır. Plugin-i dərhal 4.1.21 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What user roles can exploit CVE-2026-13169?
Users with contributor-level access and above can exploit this vulnerability.
How can this vulnerability be fixed?
It is recommended to immediately update the Eventin plugin to version 4.1.21 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.