CVE-2026-13172 PUBLISHED

Eventin < 4.1.22 - Unauthenticated Unpublished Content Disclosure

Assigner: WPScan
Reserved: 24.06.2026 Published: 26.08.2026 Updated: 26.08.2026

The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing unauthenticated users to retrieve draft, pending and private posts belonging to other users, along with the passwords and contents of password-protected ones.

Product Status

Vendor Unknown
Product Eventin
Versions Default: unaffected
  • affected from 0 to 4.1.22 (excl.)

Credits

  • Meher Sudhakar Abbireddi finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE