The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticated users to create WordPress user accounts for arbitrary email addresses and inject order records.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The Eventin WordPress plugin before version 4.1.20 contains a critical authorization bypass vulnerability in its waiting-list registration handler. This flaw allows unauthenticated attackers to create arbitrary WordPress user accounts and inject fraudulent order records without proper permission validation. Any WordPress site running the vulnerable plugin version is at risk, particularly those using Eventin for event management and ticketing. The vulnerability is especially dangerous because it enables account takeover scenarios and data manipulation at scale, potentially compromising site integrity and user trust.
While this CVE does not map to specific MITRE ATT&CK techniques, Casky's 754 security skills—powered by Claude AI's extended reasoning—would identify the underlying attack patterns associated with this vulnerability. Practitioners using Casky would detect indicators aligned with T1078 (Valid Accounts) and T1078.001 (Default Accounts), as the vulnerability enables unauthorized account creation. Security teams would also see patterns consistent with T1190 (Exploit Public-Facing Application) since the waiting-list handler is exposed without authentication. During incident investigation, Casky's skill engine would surface findings related to missing input validation (CWE-284: Improper Access Control) and help practitioners correlate suspicious account creation logs, unexpected order records, and unauthenticated API calls to the registration endpoint—enabling faster threat detection and response.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-13171. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation