What is CVE-2026-13175?
In the Eventin WordPress plugin versions prior to 4.1.21, a missing ownership check on schedule records allows users with contributor-level access and above to modify or delete entries created by other users. Immediate update to version 4.1.21 or later is required.
Azərbaycanca: Eventin WordPress plugin-inin 4.1.21-dən əvvəlki versiyalarında, planlaşdırma qeydlərinin sahibliyini yoxlamaması səbəbindən contributor səviyyəsində və daha yuxarı girişi olan istifadəçilər başqalarının yaratdığı qeydləri dəyişdirə və ya silə bilər. Plugin dərhal 4.1.21 və ya daha yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions of the Eventin WordPress plugin are affected by CVE-2026-13175?
Versions prior to 4.1.21 are affected; immediate update to version 4.1.21 or later is required.
What level of access is required to exploit CVE-2026-13175?
Users with contributor-level access and above can exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.