The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing unauthenticated users to retrieve draft, pending and private posts belonging to other users, along with the passwords and contents of password-protected ones.
We have discovered 2,411 live websites that are affected by CVE-2026-13172.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 2,411 live websites (100% of Wp Event Solution install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 120 versions ( 100% of all versions) |
| 814 websites | |
| 179 websites | |
| 155 websites | |
| 118 websites | |
| 112 websites | |
| 95 websites | |
| 94 websites | |
| 62 websites | |
| 61 websites | |
| 54 websites |
| .com | 765 websites |
| .org | 476 websites |
| .ch | 146 websites |
| .de | 82 websites |
| .nl | 69 websites |
| .ca | 56 websites |
| .it | 47 websites |
| .co.uk | 40 websites |
| .com.br | 38 websites |
| .net | 37 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | ***,*** | ||
| **********.org | ***,*** | ||
| ****.pe | ***,*** | ||
| ***********.org | ***,*** | ||
| ******.org | ***,*** | ||
| ******.com | ***,*** | ||
| **********************.org | ***,*** | ||
| ******.**.id | ***,*** | ||
| ****.de | ***,*** | ||
| ****.es | ***,*** |
FAQ