Access Control Flaw in Events Manager Plugin Allows Unauthorized User Actions
CVE-2026-18366
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 12 August 2026
Badges
What is CVE-2026-18366?
The Events Manager plugin for WordPress prior to version 7.4.1 contains a significant access control vulnerability. This flaw arises from improper scoping of capability mapping, which negates the access control measures implemented by WordPress for unrelated privileged actions. As a result, unauthenticated users can exploit this vulnerability to change passwords, escalate privileges to Administrator level, or delete accounts if the user's ID coincides with that of any of the plugin's posts. This poses a serious security risk, enabling unauthorized manipulation of user accounts.
Affected Version(s)
Events Manager 7.1 < 7.4.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.