CVE-2026-13171: Eventin < 4.1.20 - Unauthenticated Account Creation via Waiting List Endpoint
Published Aug 12, 2026
·Updated
The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticated users to create WordPress user accounts for arbitrary email addresses and inject order records.
Affected Software
1 affected component
WordPress Eventin<4.1.20
Event History
Aug 12, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-13171?
CVE-2026-13171 has a risk score of 67, indicating a medium severity vulnerability.
2
How do I fix CVE-2026-13171?
To fix CVE-2026-13171, update the Eventin WordPress plugin to version 4.1.20 or later.
3
What type of vulnerability is CVE-2026-13171?
CVE-2026-13171 is an unauthenticated account creation vulnerability in the Eventin WordPress plugin.
4
What are the effects of CVE-2026-13171?
CVE-2026-13171 allows unauthenticated users to create arbitrary WordPress user accounts and inject order records.
5
Who is affected by CVE-2026-13171?
Users of the Eventin WordPress plugin versions prior to 4.1.20 are affected by CVE-2026-13171.