PT-2026-68403 · WordPress · Events Manager
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Events Manager versions prior to 7.4
Description
An authorization check is missing on a REST route that serves temporarily stored file uploads. This allows unauthenticated users to retrieve another user's in-progress upload if the temporary identifier is known. The identifier is high-entropy, disclosed only to the uploader, and the file is removed upon submission or via scheduled cleanup, meaning a cross-user read cannot be achieved by guessing alone. The affected endpoint is 'events-manager/v1/uploads'.
Recommendations
Update to version 7.4 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Events Manager