CVE

CVE-2026-18366 — Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.4.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-18366 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.4.1 Improper Privilege Management Unknown < 7.4.1 7.4.1 2026-08-10

CVE-2026-18366

The Events Manager WordPress plugin, prior to version 7.4.1, fails to properly limit its access controls, allowing unauthorized users to bypass WordPress's existing security restrictions. This vulnerability enables attackers to modify passwords, elevate privileges to Administrator, or delete user accounts, as long as the targeted user's ID matches the ID of a post managed by the plugin.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.