Local File Inclusion Vulnerability in Events Manager Plugin for WordPress
CVE-2026-14280
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 August 2026
What is CVE-2026-14280?
The Events Manager plugin for WordPress is susceptible to Local File Inclusion through the em_options_save function across all versions up to 7.3.7.4. This vulnerability allows authenticated users with administrator-level access to include and execute arbitrary .php files residing on the server. Attackers can exploit this vulnerability to bypass access controls, access sensitive information, or run malicious PHP code if .php files can be uploaded and included. The vulnerability activates through an include_once() call during each admin_init request, notably affecting unauthenticated admin-ajax.php requests. Once a malicious key is saved by an administrator, the code inclusion occurs without any additional authentication checks.
Affected Version(s)
Events Manager β Calendar, Bookings, Tickets, and more! 0 <= 7.3.7.4