CVE-2026-62041: WordPress WP Event Manager plugin <= 3.4.1 - Broken Access Control vulnerability
Published Oct 9, 2026
·Updated
Missing Authorization vulnerability in Ashok Dudhat WP Event Manager wp-event-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Manager: from n/a through 3.4.1.
Affected Software
1 affected component
Ashok Dudhat WP Event Manager<=3.4.1
Event History
Oct 9, 2026
CVE Published
via MITRE·11:40 AM
Data Sourced
via MITRE·11:40 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
WP Event Manager versions through 3.4.1 are affected. The available data does not identify a fixed version.
2
What level of access does an attacker need?
The CVSS vector indicates that an attacker needs low-level privileges. The issue is remotely exploitable, requires no user interaction, and has low confidentiality and integrity impact.