SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-13173

LOW · CVSS 2.7 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Eventin WordPress plugin prior to version 4.1.21 is vulnerable as it fails to properly verify user permissions when assigning roles and updating user metadata during speaker creation. This flaw allows users with contributor-level access and higher to modify roles and metadata of other users, potentially leading to unauthorized privilege escalation. WordPress site administrators and security teams should prioritize this vulnerability to prevent misuse of user roles and maintain proper access controls.

CVE
CVE-2026-13173
Severity
LOW
CVSS
2.7
EPSS
0.21%
WordPress

Original NVD Description

The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users with contributor-level access and above to modify other users' roles and metadata.