CVE

CVE-2026-18057 — Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.4.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-18057 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.4.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Unknown < 7.4.1 7.4.1 2026-08-10

CVE-2026-18057

The Events Manager plugin for WordPress has a security flaw that allows attackers to inject malicious SQL code into the system. This vulnerability, which exists in versions up to 7.4.0, can be exploited by authenticated users with subscriber-level access or higher to extract sensitive information from the database. The issue arises from inadequate protection against user-supplied input and insufficient preparation of existing SQL queries.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.