Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-13174— Eventin < 4.1.21 - Contributor+ Speaker Account Deletion via IDOR

AI Predicted 8.8 Difficulty: Easy EPSS 0.32% · P25

Possible ATT&CK Techniques 1AI

T1136 · Create Account

Affected Version Matrix 1

VendorProductVersion RangeStatus
UnknownEventin< 4.1.21affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-13174

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Eventin < 4.1.21 - Contributor+ Speaker Account Deletion via IDOR
Source: CVE Program / CVE List V5
Vulnerability Description
The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
UnknownEventin 0 ~ 4.1.21 -

II. Public POCs for CVE-2026-13174

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-13174

登录查看更多情报信息。

Vendor Advisories for CVE-2026-13174 (1)

Same Patch Batch · Unknown · 2026-08-19 · 38 CVEs total

CVE-2026-14861User Verification <= 2.0.47 - Unauthenticated Arbitrary Account Lockout via IDOR
CVE-2026-18031TabaPay Gateway <= 1.4.0 - Unauthenticated Account Takeover via Payment Callback
CVE-2026-17565Animation Addons for Elementor < 2.7.2 - Unauthenticated Server-Side Request Forgery
CVE-2026-15253Easy Media Replace <= 0.2.0 - Author+ Stored XSS via Attachment Title
CVE-2026-16617Simple File List <= 6.3.11 - Unauthenticated Stored XSS via File Description
CVE-2026-16058YayCurrency < 3.3.5 - Unauthenticated Order and Vendor Financial Data Disclosure via Dokan
CVE-2026-16570NextScripts: Social Networks Auto-Poster < 4.4.8 - Reflected XSS via Facebook OAuth Callba
CVE-2026-16616Simple File List <= 6.3.11 - Unauthenticated Arbitrary File Read and Move via Path Travers
CVE-2026-14825Quiz And Survey Master < 11.2.4 - Contributor+ Arbitrary Quiz Text Settings Update via IDO
CVE-2026-14334Booking calendar, Appointment Booking System <= 3.2.36 - Unauthenticated Stored XSS via SV
CVE-2026-16979SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key En
CVE-2026-14826Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Email and Results Configuration
CVE-2026-14287TenWeb Speed Optimizer < 2.33.5 - Unauthenticated Stored XSS via Critical CSS Token Bypass
CVE-2026-14196WCFM Marketplace < 3.8.1 - Store Vendor+ Cross-Vendor Review Deletion and Status Update vi
CVE-2026-13175Eventin < 4.1.21 - Contributor+ Schedule Deletion and Modification via IDOR
CVE-2026-11565Advanced File Manager < 5.4.13 - Authenticated Arbitrary File Read and Write via fma_load_
CVE-2026-12983Dinatur <= 1.18 - Unauthenticated SQL Injection via Column Name Injection
CVE-2026-13169Eventin < 4.1.21 - Contributor+ Arbitrary Event Modification, Deletion and Ownership Takeo
CVE-2026-13173Eventin < 4.1.21 - Contributor+ User Role and Meta Modification via Speaker Creation
CVE-2026-18777TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Arbitrary Appointment Status Chan

Showing top 20 of 38 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-13174

No comments yet


Leave a comment