CVE

CVE-2026-18050 — Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-18050 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.4 Exposure of Sensitive Information to an Unauthorized Actor Unknown < 7.4 7.4 2026-08-06

CVE-2026-18050

The Events Manager plugin for WordPress, prior to version 7.4, has an issue with its REST API handling temporary file uploads. Specifically, it lacks proper authentication checks on certain routes, enabling unauthorized users to access files uploaded by other users if they know the temporary identifier assigned to that upload. This vulnerability doesn't allow attackers to guess and read arbitrary files, but rather requires knowledge of a specific identifier.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.