What is CVE-2026-13177?
CVE-2026-13177 affects the Eventin WordPress plugin before version 4.1.20, where improper access restrictions allow users with contributor-level permissions and above to read other customers' order data, including personal information, by iterating order identifiers. Updating to the latest plugin version is recommended.
Azərbaycanca: CVE-2026-13177 WordPress platformasında Eventin plaginin 4.1.20 versiyasından əvvəlki versiyalarına təsir edən boşluqdur. Bu zəiflik contributor səviyyəsində icazəyə malik istifadəçilərə sifariş identifikasiya nömrələrini ardıcıl sınamaqla digər müştərilərin şəxsi məlumatlarını oxumağa imkan verir. Plaginin son versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What level of permission is required to exploit CVE-2026-13177?
Exploiting this vulnerability requires at least contributor-level permissions in WordPress.
Which versions of the Eventin plugin are affected by CVE-2026-13177?
This vulnerability affects all versions of the Eventin plugin prior to version 4.1.20.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.