CVE-2026-13177: Eventin < 4.1.20 - Contributor+ Order Information Disclosure via IDOR
The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing users with contributor-level access and above to read other customers' order data including personal information by iterating order identifiers.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Eventin WordPress pluginto a version that resolves this vulnerability.Fixed in 4.1.20
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13177?
CVE-2026-13177 has a severity risk score of 52.
How do I fix CVE-2026-13177?
To fix CVE-2026-13177, update the Eventin plugin to version 4.1.20 or greater.
What type of vulnerability is CVE-2026-13177?
CVE-2026-13177 is an Information Disclosure vulnerability due to improper access controls.
Who is affected by CVE-2026-13177?
Users with contributor-level access and above in the Eventin WordPress plugin are affected by CVE-2026-13177.
What can attackers achieve with CVE-2026-13177?
Attackers can potentially access and read personal information from other customers' order records due to this vulnerability.