Authorization Bypass in Events Manager Plugin for WordPress
CVE-2026-10627

5.3MEDIUM

What is CVE-2026-10627?

The Events Manager plugin for WordPress is susceptible to an authorization bypass vulnerability that affects all versions up to and including 7.4.0. The flaw arises from inadequate user verification, which can permit unauthenticated attackers to access sensitive information. Specifically, this vulnerability allows unauthorized users to view titles, dates, descriptions, and location details of events marked as draft, pending, trashed, or private by administrators. As such, this puts valuable event information at risk, highlighting the need for immediate attention to secure the plugin.

Affected Version(s)

Events Manager – Calendar, Bookings, Tickets, and more! 0 <= 7.4.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

molten bit
.