CVE-2026-13174 UNKNOWN

CVE-2026-13174

Published: 2026-08-19

Description

The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…