Events Manager – Calendar, Bookings, Tickets, and more!, CVE-2026-93661
- CVE, Research URL
- Published on
- Sep 24, 2026
- Research Description
- The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any ticket on the site to their own event.
- Affected versions
-
max 7.4.5.
- Status
-
vulnerable