Sensitive Data Exposure Vulnerability in Pixelite Events Manager by WordPress
CVE-2026-105068

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 October 2026

What is CVE-2026-105068?

The Pixelite Events Manager plugin for WordPress suffers from an insertion of sensitive information into sent data vulnerability. This flaw allows an attacker to retrieve embedded sensitive data during the use of the plugin. The issue is present in all versions up to and including 7.4.5, posing a risk to users who rely on this plugin for event management. Website administrators are encouraged to review their configurations and update to secure their sensitive information.

Affected Version(s)

Events Manager 0 <= 7.4.5

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack)
.