cleantalk
Vulnerabilities and Security Researches

Events Manager – Calendar, Bookings, Tickets, and more!, CVE-2026-93661

CVE, Research URL

CVE-2026-93661

Published on
Sep 24, 2026
Research Description
The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any ticket on the site to their own event.
Affected versions
max 7.4.5.
Status
vulnerable