{"api_version":"1","generated_at":"2026-08-19T11:44:42+00:00","cve":"CVE-2026-13173","urls":{"html":"https://cve.report/CVE-2026-13173","api":"https://cve.report/api/cve/CVE-2026-13173.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-13173","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-13173"},"summary":{"title":"Eventin < 4.1.21 - Contributor+ User Role and Meta Modification via Speaker Creation","description":"The Eventin  WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users with contributor-level access and above to modify other users' roles and metadata.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-08-19 06:17:31","updated_at":"2026-08-19 06:17:31"},"problem_types":["CWE-862 Missing Authorization"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/f1bb2ee8-85b2-415e-ab41-97b9958e5e70/","name":"https://wpscan.com/vulnerability/f1bb2ee8-85b2-415e-ab41-97b9958e5e70/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-13173","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13173","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Eventin","version":"affected 4.1.21 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Meher Sudhakar Abbireddi","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Eventin","vendor":"Unknown","versions":[{"lessThan":"4.1.21","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Meher Sudhakar Abbireddi"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Eventin  WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users with contributor-level access and above to modify other users' roles and metadata."}],"problemTypes":[{"descriptions":[{"description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-19T06:00:14.418Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/f1bb2ee8-85b2-415e-ab41-97b9958e5e70/"}],"source":{"discovery":"EXTERNAL"},"title":"Eventin < 4.1.21 - Contributor+ User Role and Meta Modification via Speaker Creation","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-13173","datePublished":"2026-08-19T06:00:14.418Z","dateReserved":"2026-06-24T13:24:41.332Z","dateUpdated":"2026-08-19T06:00:14.418Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-19 06:17:31","lastModifiedDate":"2026-08-19 06:17:31","problem_types":["CWE-862 Missing Authorization"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"13173","Ordinal":"1","Title":"Eventin < 4.1.21 - Contributor+ User Role and Meta Modification ","CVE":"CVE-2026-13173","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"13173","Ordinal":"1","NoteData":"The Eventin  WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users with contributor-level access and above to modify other users' roles and metadata.","Type":"Description","Title":"Eventin < 4.1.21 - Contributor+ User Role and Meta Modification "}]}}}