Local File Inclusion Vulnerability in Events Manager Plugin for WordPress
CVE-2026-14280

6.6MEDIUM

What is CVE-2026-14280?

The Events Manager plugin for WordPress is susceptible to Local File Inclusion through the em_options_save function across all versions up to 7.3.7.4. This vulnerability allows authenticated users with administrator-level access to include and execute arbitrary .php files residing on the server. Attackers can exploit this vulnerability to bypass access controls, access sensitive information, or run malicious PHP code if .php files can be uploaded and included. The vulnerability activates through an include_once() call during each admin_init request, notably affecting unauthenticated admin-ajax.php requests. Once a malicious key is saved by an administrator, the code inclusion occurs without any additional authentication checks.

Affected Version(s)

Events Manager – Calendar, Bookings, Tickets, and more! 0 <= 7.3.7.4

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.