CVE Database /
CVE-2026-18050
CVE
CVE-2026-18050 — Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-18050
|
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.4 |
Exposure of Sensitive Information to an Unauthorized Actor |
Unknown
|
< 7.4
|
7.4 |
2026-08-06 |
—
|
CVE-2026-18050
The Events Manager plugin for WordPress, prior to version 7.4, has an issue with its REST API handling temporary file uploads. Specifically, it lacks proper authentication checks on certain routes, enabling unauthorized users to access files uploaded by other users if they know the temporary identifier assigned to that upload. This vulnerability doesn't allow attackers to guess and read arbitrary files, but rather requires knowledge of a specific identifier.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings