What is CVE-2026-18366?
The Events Manager WordPress plugin before version 7.4.1 has improperly scoped capability mapping, allowing unauthenticated attackers to change passwords, escalate privileges to Administrator, or delete any account. Immediate update to version 7.4.1 or later is recommended.
Azərbaycanca: Events Manager WordPress plaqinində (7.4.1-dən əvvəlki versiyalar) icazə xəritələnməsi səhv konfiqurasiya edildiyi üçün autentifikasiya olunmamış istifadəçilər ixtiyari hesabların parolunu dəyişə, administrator səlahiyyətləri əldə edə və ya hesabları silə bilər. Plaqini dərhal 7.4.1 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of the Events Manager plugin are affected by CVE-2026-18366?
This vulnerability affects all versions of the Events Manager WordPress plugin before version 7.4.1.
What can an unauthenticated attacker do by exploiting CVE-2026-18366?
Due to improperly scoped capability mapping, unauthenticated attackers can change passwords of arbitrary accounts, escalate privileges to Administrator, or delete accounts.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.