The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing unauthenticated users to retrieve draft, pending and private posts belonging to other users, along with the passwords and contents of password-protected ones.
Metrics
Affected Vendors & Products
References
History
Wed, 26 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing unauthenticated users to retrieve draft, pending and private posts belonging to other users, along with the passwords and contents of password-protected ones. | |
| Title | Eventin < 4.1.22 - Unauthenticated Unpublished Content Disclosure | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-26T06:00:17.901Z
Reserved: 2026-06-24T13:24:39.499Z
Link: CVE-2026-13172
No data.
No data.
No data.
OpenCVE Enrichment
No data.