Unauthorized Account Creation in Eventin WordPress Plugin
CVE-2026-13171
Currently unrated
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-13171?
The Eventin WordPress plugin prior to version 4.1.20 has a flaw that lacks proper authorization checks on its waiting-list registration handler. This vulnerability allows unauthenticated users to create WordPress user accounts linked to arbitrary email addresses, leading to potential misuse and injection of order records. It poses a significant risk, as it can enable malicious activities on affected WordPress sites.
Affected Version(s)
Eventin 0 < 4.1.20
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.