What is CVE-2026-13174?
CVE-2026-13174 is a missing authorization check in the Eventin WordPress plugin (versions before 4.1.21) before deleting user accounts. It allows users with 'Contributor' level access or above to permanently delete accounts of other users. Immediate update to the latest plugin version is required.
Azərbaycanca: CVE-2026-13174, Eventin WordPress plaginində (4.1.21-dən əvvəlki versiyalarda) hesab sahibliyi və ya səlahiyyət yoxlaması çatışmazlığıdır. Bu, 'Contributor' və daha yuxarı səviyyəli istifadəçilərə digər istifadəçi hesablarını qalıcı olaraq silməyə imkan verir. Plagin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
What versions of the Eventin WordPress plugin are affected by CVE-2026-13174 and what is the main risk?
The vulnerability affects Eventin plugin versions before 4.1.21. The main risk is the missing authorization check that allows users with Contributor level access or above to permanently delete accounts of other users.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.