CVE-2026-13171
The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unaut
CVSS
8.2
Alto
EPSS
0.2%
p14
KEV
—
Exploit Today
4
0-100
Publicado: 12 ago 2026 · Última mod.: 26 ago 2026 · CWE-284
0.1%EPSS · 30 días0.2%
2026-08-122026-08-26
The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticated users to create WordPress user accounts for arbitrary email addresses and inject order records.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-614197.8 ALT0.7%
——0Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.3dCVE-2026-782457.3 ALT39.0%
——12A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack may be launched remotely. The exploit has been published and may be used.3dCVE-2026-782027.3 ALT20.8%
——6A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_settings of the file admin_class.php. The manipulation of the argument img results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and could be used.3dCVE-2026-76609—14.8%
——4Joomla Extension - fabrikar.com - Unauthenticated modification of any comment in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.3dCVE-2026-76608—21.6%
——6Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access checks.3dCVE-2026-76607—14.8%
——4Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.3d