PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-13174 Eventin CVE debrief

The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts. This vulnerability has significant implications for user account security and could potentially impact the integrity of affected deployments. Administrators and users of the Eventin WordPress plugin should be aware of this vulnerability and take necessary precautions to protect their environments. Evidence from multiple sources confirms the presence of this vulnerability, but the exact scope of affected deployments remains unclear. Defenders should verify the presence of this vulnerability in their environments and review user account activity for suspicious deletion events.

Vendor
Eventin
Product
Eventin WordPress plugin
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-08-26
Advisory published
2026-08-19
Advisory updated
2026-08-26

Who should care

Administrators and users of the Eventin WordPress plugin, as well as security teams monitoring for potential vulnerabilities in WordPress plugins, should be aware of this vulnerability and take necessary precautions to protect their environments. This includes reviewing user account activity and audit logs for suspicious deletion events, and restricting user account deletion capabilities to authorized administrators. Additionally, security teams should consider the potential impact on user account security and prioritize remediation efforts accordingly.

Technical summary

The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts. This vulnerability has a CVSS score of 7.2 and is classified as HIGH severity. The vulnerability affects the Eventin WordPress plugin and could potentially impact user account security. Affected deployments may be vulnerable to unauthorized user account deletion.

Defensive priority

High priority due to potential for significant impact on user account security.

Recommended defensive actions

  • Review and update the Eventin WordPress plugin to version 4.1.21 or later.
  • Restrict user account deletion capabilities to authorized administrators.
  • Monitor user account activity and audit logs for suspicious deletion events.

Evidence notes

The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts. Evidence from the NVD and WPScan suggests that the Eventin WordPress plugin has a vulnerability allowing unauthorized user account deletion. This vulnerability has been confirmed by multiple sources, including the CVE Program and NIST NVD. However, the exact scope of affected deployments and potential impact on user account security remains unclear. Defenders should verify the presence of this vulnerability in their environments and review user account activity for suspicious deletion events.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-13174 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-13174

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-13174 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-13174

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.