CVE-2026-93662: Events Manager 7.4.1 - 7.4.4 - Subscriber+ Unpublished Event and Location Disclosure via 'owner' Parameter
Published Sep 24, 2026
·Updated
The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search when a caller supplies their own owner value, letting a low-privileged user read other accounts' unpublished, pending or trashed event and venue content, including full street addresses.
Affected Software
1 affected component
Events Manager<7.4.5
Event History
Sep 24, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
Description
Frequently Asked Questions
1
Who can exploit this issue?
Any authenticated user with Subscriber-level access or higher can exploit it. The issue affects searches for events and locations when the caller supplies an owner value.
2
What information could be exposed?
An attacker can read other users' unpublished, pending, or trashed event and venue content. Exposed venue data can include full street addresses.
3
Which plugin versions are affected?
Events Manager versions 7.4.1 through 7.4.4 are affected. The issue is fixed in version 7.4.5.