Access Control Flaw in Eventin WordPress Plugin from Eventin
CVE-2026-13168
Currently unrated
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-13168?
The Eventin WordPress plugin has a security flaw that allows users with contributor-level access and above to view sensitive customer information stored in the system. This flaw arises from inadequate access controls, permitting unauthorized users to read personal data, such as names and email addresses, of other customers. It is essential for administrators to update the plugin to version 4.1.20 or later to mitigate this issue and protect user privacy.
Affected Version(s)
Eventin 0 < 4.1.20
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.