AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-13168

MEDIUM · CVSS 6.5 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Eventin WordPress plugin prior to version 4.1.20 has a vulnerability that allows users with contributor-level access and higher to access and read stored personal data of other customers, including names and email addresses. This exposure of sensitive information could lead to privacy breaches and unauthorized data access. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential risks.

CVE
CVE-2026-13168
Severity
MEDIUM
CVSS
6.5
EPSS
0.27%
WordPress

Original NVD Description

The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users with contributor-level access and above to read other customers' personal data such as names and email addresses.