PT-2026-71024 · WordPress · Events Manager
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Events Manager versions prior to 7.4.1
Description
The plugin fails to properly scope its capability mapping, which overrides the access control decisions made by WordPress for unrelated privileged actions. This flaw allows unauthenticated users to change passwords, escalate privileges to Administrator, or delete any account if the user ID matches the ID of one of the plugin's own posts.
Recommendations
Update to version 7.4.1 or later.
Exploit
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Events Manager