AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-13177

MEDIUM · CVSS 4.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Eventin WordPress plugin prior to version 4.1.20 has a vulnerability that permits users with contributor-level access and higher to access and read other customers' order records, which may include sensitive personal information. This flaw arises from inadequate access controls, enabling unauthorized data exposure through order identifier enumeration. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.

CVE
CVE-2026-13177
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%
WordPress

Original NVD Description

The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing users with contributor-level access and above to read other customers' order data including personal information by iterating order identifiers.