SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-13172

MEDIUM · CVSS 5.3 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Eventin WordPress plugin prior to version 4.1.22 is vulnerable due to insufficient access controls in its REST API, enabling unauthenticated users to access draft, pending, and private posts from other users, including sensitive information from password-protected content. This exposure can lead to unauthorized data disclosure, impacting user privacy and content integrity. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential risks.

CVE
CVE-2026-13172
Severity
MEDIUM
CVSS
5.3
EPSS
0.31%
WordPress

Original NVD Description

The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing unauthenticated users to retrieve draft, pending and private posts belonging to other users, along with the passwords and contents of password-protected ones.