All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-13168
MEDIUMpublished 2026-08-12 06:17 UTC · 21 hours ago · modified 2026-08-12 20:17 UTC
6.5
CVSS / 10
// description
The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users with contributor-level access and above to read other customers' personal data such as names and email addresses.
// weaknesses (CWE)
- CWE-200