Junglewise Threat Intelligence

CVE-2026-13172: Eventin WordPress plugin unauthenticated content disclosure in REST API

CVE-2026-13172 · Severity: medium · CVSS 5.3 · Published 2026-08-26

Vendors: Eventin.

Executive brief

Eventin is a popular WordPress plugin for managing events and ticket sales. The plugin's REST API fails to properly restrict access to unpublished and password-protected event content, allowing anyone to retrieve draft posts, private event details, and password-protected event information without logging in or entering a password. This exposes sensitive event data and passwords that should remain confidential.

Technical details

The vulnerability is a broken access control issue (CWE-862) in the Eventin plugin's REST API endpoints (specifically the eventin/v1/event namespace). The plugin fails to validate user authorization or content status before serving event data via REST calls. An unauthenticated attacker can obtain a REST nonce from any public page and use it to query endpoints like /wp-json/eventin/v1/event/events and /wp-json/eventin/v1/event/seatmap_details to retrieve password-protected event content (including plaintext passwords), draft posts, pending posts, and private posts belonging to other users. This bypasses WordPress's native content access controls. The vulnerability was partially patched in versions 4.1.20–4.1.21 but fully fixed in version 4.1.22.

Affected products

  • Eventin Eventin before 4.1.22

Timeline

  • 2026-08-24: disclosed
  • 2026-08-26: patched: Fixed in version 4.1.22

References