๐Ÿ” CVE Alert

CVE-2026-18050

UNKNOWN 0.0

Events Manager < 7.4 - Unauthenticated Pending Upload Disclosure via events-manager/v1/uploads

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve another user's in-progress upload when its temporary identifier is known. The identifier is high-entropy, is disclosed only to the uploader, and the file is removed on submission or by a scheduled cleanup, so a cross-user read is not achievable by guessing alone.

Vendor unknown
Product events manager
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for unknown events manager

Be the first to know when new unknown vulnerabilities affecting unknown events manager are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Events Manager
0 < 7.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/84964951-d25a-4753-bf71-fe00e2492a89/

Credits

Usama Arshad WPScan