PT-2026-68403 · WordPress · Events Manager

·

CVE-2026-18050

·

Published

2026-08-06

·

Updated

2026-08-06

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Events Manager versions prior to 7.4
Description An authorization check is missing on a REST route that serves temporarily stored file uploads. This allows unauthenticated users to retrieve another user's in-progress upload if the temporary identifier is known. The identifier is high-entropy, disclosed only to the uploader, and the file is removed upon submission or via scheduled cleanup, meaning a cross-user read cannot be achieved by guessing alone. The affected endpoint is 'events-manager/v1/uploads'.
Recommendations Update to version 7.4 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18050

Affected Products

Events Manager