CVE-2026-13172: Eventin < 4.1.22 - Unauthenticated Unpublished Content Disclosure
The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing unauthenticated users to retrieve draft, pending and private posts belonging to other users, along with the passwords and contents of password-protected ones.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/plugin/eventinto a version that resolves this vulnerability.Fixed in 4.1.22 - Compensating control
Restrict network/firewall access to the Eventin plugin REST API namespace until the WordPress plugin is upgraded to 4.1.22.
Event History
Frequently Asked Questions
Which content can be exposed through the affected REST API?
Unauthenticated users can retrieve draft, pending, and private posts owned by other users. Password-protected posts may also be exposed, including their passwords and contents.
Who can exploit this issue?
No authentication is required. Any user able to access the affected REST API namespace can attempt to retrieve the non-published content.
Which plugin versions are affected?
Eventin versions before 4.1.22 are affected. Version 4.1.22 is the first version identified as not affected.