CVE · High

CVE-2026-57713 — Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.3.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-57713 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.3.7 High 8.8 < 7.3.7 7.3.7 2026-07-08

CVE-2026-57713

The Events Manager plugin for WordPress contains a vulnerability that can be exploited through PHP Object Injection, allowing unauthenticated attackers to inject malicious objects into the application. This flaw is present in versions up to 7.3.6 and can lead to severe consequences if an additional plugin or theme introduces a POP chain, enabling the attacker to delete files, access sensitive data, or execute code.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.