Description
The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing unauthenticated users to retrieve draft, pending and private posts belonging to other users, along with the passwords and contents of password-protected ones.
Published: 2026-08-26
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Eventin WordPress plugin version prior to 4.1.22 exposes its REST API endpoints without properly checking the status or ownership of content. This allows anyone to query draft, pending, or private posts and uncover not only the content but also passwords used to protect those posts. The flaw results in a disclosure of sensitive information to unauthenticated users, potentially revealing confidential data and login credentials. The weakness is a classic access‑control failure where content should be protected by status or ownership checks but is not, leading to data confidentiality loss.

Affected Systems

WordPress installations running the Eventin plugin before version 4.1.22 are affected. The plugin is identified as Unknown:Eventin in the CNA list. No specific WordPress core or other products are listed as affected.

Risk and Exploitability

The vulnerability can be exploited remotely by simply making a request to the vulnerable REST endpoint; no authentication or privileged status is required. The EPSS score is not available, and the issue is not yet listed in the CISA KEV catalog, indicating that no mass exploitation has been observed. Nonetheless, the flaw allows full disclosure of unpublished content and passwords, so the risk is high for sites with sensitive drafts. The likelihood of exploitation is potentially moderate because the endpoint is publicly reachable and no user interaction is needed.

Generated by OpenCVE AI on August 26, 2026 at 07:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Eventin to version 4.1.22 or later.
  • If an upgrade is not possible, disable the Eventin plugin until the vulnerability is patched.
  • Restrict access to the Eventin REST API by limiting it to authenticated users with appropriate roles or by implementing firewall rules that block the affected endpoints.

Generated by OpenCVE AI on August 26, 2026 at 07:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Eventin
Eventin eventin
Wordpress
Wordpress wordpress
Vendors & Products Eventin
Eventin eventin
Wordpress
Wordpress wordpress

Wed, 26 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 26 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing unauthenticated users to retrieve draft, pending and private posts belonging to other users, along with the passwords and contents of password-protected ones.
Title Eventin < 4.1.22 - Unauthenticated Unpublished Content Disclosure
References

Subscriptions

Eventin Eventin
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-26T06:00:17.901Z

Reserved: 2026-06-24T13:24:39.499Z

Link: CVE-2026-13172

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T08:00:02Z

Weaknesses