PT-2026-71024 · WordPress · Events Manager

·

CVE-2026-18366

·

Published

2026-08-12

·

Updated

2026-08-12

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Events Manager versions prior to 7.4.1
Description The plugin fails to properly scope its capability mapping, which overrides the access control decisions made by WordPress for unrelated privileged actions. This flaw allows unauthenticated users to change passwords, escalate privileges to Administrator, or delete any account if the user ID matches the ID of one of the plugin's own posts.
Recommendations Update to version 7.4.1 or later.

Exploit

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18366

Affected Products

Events Manager