PT-2026-81164 · WordPress · Events Manager

·

CVE-2026-14280

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Events Manager – Calendar, Bookings, Tickets, and more! versions prior to 7.3.7.5
Description An issue exists in the em options save() function that allows authenticated attackers with administrator-level access to perform Local File Inclusion. This occurs when a malicious traversal key is stored and subsequently executed via an include once() call during every admin init invocation, including unauthenticated admin-ajax.php requests. This can lead to the execution of arbitrary PHP code if .php files can be uploaded, enabling attackers to bypass access controls or obtain sensitive data.
Recommendations Update to version 7.3.7.5 or later. As a temporary mitigation, restrict administrator-level access to the em options save() function.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14280

Affected Products

Events Manager