VYPR
Low severity2.7NVD Advisory· Published Aug 19, 2026· Updated Aug 26, 2026

CVE-2026-13173

CVE-2026-13173

Description

The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users with contributor-level access and above to modify other users' roles and metadata.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

1