What is CVE-2026-13173?
This vulnerability exists in Eventin WordPress plugin versions before 4.1.21, which fails to verify user permissions during speaker creation. It allows users with contributor-level access to modify other users' roles and metadata. The plugin should be immediately updated to the latest version.
Azərbaycanca: Bu boşluq Eventin WordPress plagininin 4.1.21-dən əvvəlki versiyalarında mövcuddur və istifadəçi icazələrini düzgün yoxlamır. Contributor səviyyəsində girişi olan şəxslərə başqa istifadəçilərin rollarını dəyişməyə imkan verir. Plagin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which plugin does the CVE-2026-13173 vulnerability affect?
This vulnerability affects the Eventin WordPress plugin.
What level of access does an attacker need to exploit CVE-2026-13173?
The attacker needs contributor-level access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.