CVE-2026-13175: Eventin < 4.1.21 - Contributor+ Schedule Deletion and Modification via IDOR
The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with contributor-level access and above to alter or delete schedule entries created by other users.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A user with contributor-level access or higher can exploit it. The issue allows them to modify or delete schedule entries created by other users.
Are sites affected by default?
A site is affected if it uses the Eventin WordPress plugin at a version earlier than 4.1.21 and has users with contributor-level or higher access who can interact with schedule records.
What should be done if immediate patching is not possible?
Restrict contributor-level and higher access to trusted users, especially accounts able to interact with Eventin schedule records. Review and limit user roles until the plugin can be updated to version 4.1.21 or later.
How can administrators check for possible impact?
Review Eventin schedule entries for unexpected modifications or deletions, particularly changes associated with contributor-level or other non-owner accounts. Check WordPress user accounts and role assignments for untrusted users with contributor access or higher.