What is CVE-2026-13171?
The Eventin WordPress plugin before version 4.1.20 lacks an authorization check in its waiting-list registration handler, enabling unauthenticated users to create WordPress user accounts for arbitrary email addresses and inject order records. Immediate update to version 4.1.20 or later is recommended.
Azərbaycanca: Eventin (4.1.20-dən əvvəlki versiyalar) WordPress pluginində authorization check-in olmaması səbəbindən, autentifikasiya olunmamış istifadəçilər ixtiyari e-poçt ünvanları üçün WordPress istifadəçi hesabı yarada və sifariş qeydləri yeridə bilərlər. Plugin'i dərhal 4.1.20 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Eventin plugin are affected by CVE-2026-13171?
This vulnerability affects all versions of the Eventin plugin prior to 4.1.20.
What can an unauthenticated attacker do via CVE-2026-13171?
Due to a missing authorization check in the waiting-list registration handler, unauthenticated users can create WordPress user accounts for arbitrary email addresses and inject order records.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.