CVE-2026-18366: Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress already made for unrelated privileged actions, which allows unauthenticated users to change the password of, escalate to Administrator, or delete any account whose user ID happens to match the ID of one of the Events Manager WordPress plugin before 7.4.1's own posts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18366?
CVE-2026-18366 has a risk rating of 89, which indicates a high severity vulnerability.
How do I fix CVE-2026-18366?
To fix CVE-2026-18366, update the Events Manager WordPress plugin to version 7.4.1 or later.
What are the consequences of CVE-2026-18366?
CVE-2026-18366 allows unauthenticated users to escalate privileges to Administrator, change passwords, and delete accounts.
Which version of the Events Manager plugin is affected by CVE-2026-18366?
CVE-2026-18366 affects all versions of the Events Manager plugin prior to 7.4.1.
Is user authentication required to exploit CVE-2026-18366?
No, CVE-2026-18366 can be exploited by unauthenticated users.