Back

CRITICAL

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

Published Aug 12, 2026

Description

The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress already made for unrelated privileged actions, which allows unauthenticated users to change the password of, escalate to Administrator, or delete any account whose user ID happens to match the ID of one of the Events Manager WordPress plugin before 7.4.1's own posts.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Aug 12, 2026
Updated Aug 12, 2026
Reserved Jul 30, 2026
CISA Vulnrichment
Updated Aug 12, 2026
NVD
Status Deferred
Modified Aug 26, 2026
Red Hat
Severity n/a
Public date n/a