What is CVE-2026-18050?
CVE-2026-18050 is a vulnerability in the 'Events Manager' WordPress plugin before version 7.4. It lacks authorization checks on a REST route handling temporary file uploads, allowing unauthenticated users to access another user's in-progress uploads if the high-entropy temporary identifier is known. Administrators should update the plugin immediately.
Azərbaycanca: CVE-2026-18050 'Events Manager' WordPress plugin-inin 7.4-dən əvvəlki versiyalarında müəyyən edilmiş boşluqdur. Plugin REST route üzərində avtorizasiya yoxlaması aparmır, bu da autentifikasiya olunmamış şəxslərə müvəqqəti identifikator vasitəsilə digər istifadəçilərin yüklənən fayllarına icazəsiz giriş imkanı yaradır. Sayt inzibatçıları plaqini dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What versions of the 'Events Manager' plugin are affected by CVE-2026-18050?
This vulnerability exists in versions of the 'Events Manager' WordPress plugin before 7.4.
What can an attacker gain unauthorized access to by exploiting CVE-2026-18050?
An unauthenticated user can gain unauthorized access to another user's in-progress uploads via a temporary identifier.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.