PatchSiren cyber security CVE debrief
CVE-2026-13174 Eventin CVE debrief
The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts. This vulnerability has significant implications for user account security and could potentially impact the integrity of affected deployments. Administrators and users of the Eventin WordPress plugin should be aware of this vulnerability and take necessary precautions to protect their environments. Evidence from multiple sources confirms the presence of this vulnerability, but the exact scope of affected deployments remains unclear. Defenders should verify the presence of this vulnerability in their environments and review user account activity for suspicious deletion events.
- Vendor
- Eventin
- Product
- Eventin WordPress plugin
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-26
Who should care
Administrators and users of the Eventin WordPress plugin, as well as security teams monitoring for potential vulnerabilities in WordPress plugins, should be aware of this vulnerability and take necessary precautions to protect their environments. This includes reviewing user account activity and audit logs for suspicious deletion events, and restricting user account deletion capabilities to authorized administrators. Additionally, security teams should consider the potential impact on user account security and prioritize remediation efforts accordingly.
Technical summary
The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts. This vulnerability has a CVSS score of 7.2 and is classified as HIGH severity. The vulnerability affects the Eventin WordPress plugin and could potentially impact user account security. Affected deployments may be vulnerable to unauthorized user account deletion.
Defensive priority
High priority due to potential for significant impact on user account security.
Recommended defensive actions
- Review and update the Eventin WordPress plugin to version 4.1.21 or later.
- Restrict user account deletion capabilities to authorized administrators.
- Monitor user account activity and audit logs for suspicious deletion events.
Evidence notes
The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts. Evidence from the NVD and WPScan suggests that the Eventin WordPress plugin has a vulnerability allowing unauthorized user account deletion. This vulnerability has been confirmed by multiple sources, including the CVE Program and NIST NVD. However, the exact scope of affected deployments and potential impact on user account security remains unclear. Defenders should verify the presence of this vulnerability in their environments and review user account activity for suspicious deletion events.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-13174 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-13174
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-13174 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-13174
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/849478d1-640f-49e0-8fa5-918e41654923/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.