CVE-2026-13174: Eventin < 4.1.21 - Contributor+ Speaker Account Deletion via IDOR
The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated user with contributor-level access or higher can exploit it. The vulnerable plugin does not verify that the requester owns the target account or has the required capability to delete it.
What is the impact of successful exploitation?
An attacker can permanently delete other user accounts. This could include accounts belonging to other site users if the attacker can target their account identifiers.
Which installations are affected?
WordPress sites using Eventin versions earlier than 4.1.21 are affected. Sites running version 4.1.21 or later are not identified as affected by the provided information.