A vulnerability, which was classified as critical , was found in Eventin Plugin up to 4.1.19 on WordPress. This impacts an unknown function of the component Registration Handler . Executing a manipulation can lead to improper access controls. This vulnerability is handled as CVE-2026-13171 . The attack can be executed remotely. There is not any exploit available. You should upgrade the affected component.