Feed/CVE-2026-13177
CVE-2026-13177

CVE-2026-13177

Published Aug 12, 2026·Updated Aug 12, 2026

NVD Description

The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing users with contributor-level access and above to read other customers' order data including personal information by iterating order identifiers.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free