SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-13176

LOW · CVSS 2.7 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Eventin WordPress plugin prior to version 4.1.21 is vulnerable due to inadequate validation of user-supplied webhook URLs, enabling users with contributor-level access or higher to initiate blind server-side requests to arbitrary external hosts. This could lead to potential information leakage or further exploitation of the server. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-13176
Severity
LOW
CVSS
2.7
EPSS
0.24%
WordPress

Original NVD Description

The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify event ownership, allowing users with contributor-level access and above to trigger blind server-side requests to arbitrary hosts.