CVE-2026-18366
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress already made for unrelated privileged actions, which allows unauthenticated users to change the password of, escalate to Administrator, or delete any account whose user ID happens to match the ID of one of the Events Manager WordPress plugin before 7.4.1's own posts.
| Vendor | unknown |
| Product | events manager |
| Published | Aug 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown events manager
Be the first to know when new unknown vulnerabilities affecting unknown events manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Events Manager
7.1 < 7.4.1
References
Credits
Jakub Herman WPScan