CVE Database /
CVE-2026-13171
CVE
CVE-2026-13171 — Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.20
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-13171
|
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.20 |
Improper Access Control |
Unknown
|
< 4.1.20
|
4.1.20 |
2026-08-10 |
—
|
CVE-2026-13171
The Eventin plugin for WordPress contains a vulnerability that allows an unauthorized attacker to create user accounts, even when user registration is disabled, affecting all versions of the plugin up to 4.1.20. This issue enables an attacker to create new user accounts without authentication, potentially leading to unauthorized access and other security risks.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings