CVE-2026-13169: Eventin < 4.1.21 - Contributor+ Arbitrary Event Modification, Deletion and Ownership Takeover via IDOR
Published Aug 19, 2026
·Updated
The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned to a different author, allowing users with contributor-level access and above to alter, delete, or take over events created by other users including administrators.
Affected Software
1 affected component
WordPress plugin Eventin<4.1.21
Event History
Aug 19, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A user with contributor-level access or higher can exploit it. The affected actions can target events created by other users, including administrators.
2
What can an attacker do with access to a contributor account?
They can modify or delete other users' events, or reassign those events to themselves to take ownership.
3
Which versions are affected?
Eventin versions before 4.1.21 are affected.