CVE Database /
CVE-2026-18057
CVE
CVE-2026-18057 — Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.4.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-18057
|
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.4.1 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Unknown
|
< 7.4.1
|
7.4.1 |
2026-08-10 |
—
|
CVE-2026-18057
The Events Manager plugin for WordPress has a security flaw that allows attackers to inject malicious SQL code into the system. This vulnerability, which exists in versions up to 7.4.0, can be exploited by authenticated users with subscriber-level access or higher to extract sensitive information from the database. The issue arises from inadequate protection against user-supplied input and insufficient preparation of existing SQL queries.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings