What is CVE-2026-18057?
CVE-2026-18057 is an SQL injection vulnerability in the Events Manager WordPress plugin. It affects versions before 7.4.1, allowing users with subscriber-level access to tamper with other people's booking consent records. Immediate update to the latest version is required.
Azərbaycanca: CVE-2026-18057, Events Manager WordPress plaginində aşkarlanmış SQL injection zəifliyidir. 7.4.1 versiyasından əvvəlki versiyalara təsir edir və abunəçi hüquqlarına malik istifadəçilərin başqalarının bron razılığı qeydlərini dəyişdirməsinə imkan verir. Plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the Events Manager plugin are affected by CVE-2026-18057?
This vulnerability affects versions of the Events Manager WordPress plugin prior to 7.4.1.
What level of user can tamper with other people's consent records using CVE-2026-18057?
Users with subscriber-level access can exploit this SQL injection vulnerability to tamper with other people's booking consent records.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.