The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The Eventin WordPress plugin before version 4.1.21 contains an improper access control vulnerability (CWE-284) that allows any user with contributor-level privileges or higher to permanently delete arbitrary user accounts without ownership verification. This is particularly dangerous in multi-author WordPress environments where contributors should have limited administrative capabilities. Website administrators, content teams, and any organization using Eventin for event management face significant risks of account compromise, data loss, and operational disruption. A malicious or compromised contributor account could systematically remove legitimate users, including administrators, effectively locking them out of the platform.
While this CVE doesn't map directly to specific MITRE ATT&CK techniques, Casky's Claude-powered analysis would identify the underlying patterns associated with Privilege Escalation (T1548) and Account Manipulation (T1098) tactics. Security practitioners using Casky would detect anomalous account deletion patterns—specifically multiple deletions originating from lower-privileged accounts—as a key indicator of exploitation. The platform's extended reasoning capabilities would help correlate user permission levels with administrative actions, flagging instances where contributor-level accounts execute high-impact operations typically reserved for administrators. By mapping this vulnerability against authorization control behaviors, practitioners can identify suspicious activity chains and implement compensating controls while awaiting the plugin update to version 4.1.21 or later.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-13174. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation