๐Ÿ” CVE Alert

CVE-2026-93661

UNKNOWN 0.0

Events Manager < 7.4.5 - Contributor+ Arbitrary Ticket Overwrite via IDOR

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any ticket on the site to their own event.

Vendor unknown
Product events manager
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for unknown events manager

Be the first to know when new unknown vulnerabilities affecting unknown events manager are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Events Manager
0 < 7.4.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/8f1c665e-15e4-4b5d-853d-919723614611/

Credits

Hasyros WPScan