CVE Database /
CVE-2026-18366
CVE
CVE-2026-18366 — Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.4.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-18366
|
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.4.1 |
Improper Privilege Management |
Unknown
|
< 7.4.1
|
7.4.1 |
2026-08-10 |
—
|
CVE-2026-18366
The Events Manager WordPress plugin, prior to version 7.4.1, fails to properly limit its access controls, allowing unauthorized users to bypass WordPress's existing security restrictions. This vulnerability enables attackers to modify passwords, elevate privileges to Administrator, or delete user accounts, as long as the targeted user's ID matches the ID of a post managed by the plugin.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings