Description
The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts.
Published: 2026-08-19
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Eventin WordPress plugin before version 4.1.21 fails to check who owns an account or whether the requesting user has the proper capability before allowing a user account to be deleted. This flaw allows any user with a contributor‑level role or higher to permanently delete other users’ accounts. The resulting loss of user data can disrupt service for those users and erode trust in the platform.

Affected Systems

The vulnerability affects the Eventin WordPress plugin in all versions released before 4.1.21. No other WordPress core, plugin, or third‑party components are listed as affected.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests a low probability of automated exploitation. The issue is not included in the CISA KEV catalog. Attacks are inferred to be remote, carried out via the plugin’s HTTP endpoints, and require an authenticated contributor‑level or higher account. Upon successful exploitation, an attacker can delete an arbitrary user account but does not gain code execution or system‑wide access beyond this destructive capability.

Generated by OpenCVE AI on August 20, 2026 at 17:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Eventin plugin to version 4.1.21 or later.
  • If an immediate update is not possible, remove or further restrict the “delete user” capability from contributor, speaker, and other non‑administrator roles through WordPress role management.
  • Enable logging of account‑deletion events and audit the logs regularly for unauthorized activity.

Generated by OpenCVE AI on August 20, 2026 at 17:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Eventin
Eventin eventin
Wordpress
Wordpress wordpress
Vendors & Products Eventin
Eventin eventin
Wordpress
Wordpress wordpress

Wed, 19 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts.
Title Eventin < 4.1.21 - Contributor+ Speaker Account Deletion via IDOR
References

Subscriptions

Eventin Eventin
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-19T12:57:08.978Z

Reserved: 2026-06-24T13:24:43.073Z

Link: CVE-2026-13174

cve-icon Vulnrichment

Updated: 2026-08-19T12:57:00.628Z

cve-icon NVD

Status : Deferred

Published: 2026-08-19T06:17:32.200

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-13174

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T17:30:03Z

Weaknesses