cleantalk
Vulnerabilities and Security Researches

Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin, CVE-2026-13174

CVE, Research URL

CVE-2026-13174

Published on
Aug 19, 2026
Research Description
The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts.
Affected versions
max 4.1.21.
Status
vulnerable