Feed/CVE-2026-13171
CVE-2026-13171HIGHCVSS 8.2

CVE-2026-13171

Published Aug 12, 2026·Updated Aug 12, 2026

NVD Description

The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticated users to create WordPress user accounts for arbitrary email addresses and inject order records.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free