SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-10627

MEDIUM · CVSS 5.3 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Events Manager plugin for WordPress is susceptible to an authorization bypass vulnerability, allowing unauthenticated attackers to access sensitive event information, including titles and locations, that should be restricted. This issue affects all versions up to 7.4.0 and poses a risk to the confidentiality of event data. WordPress site administrators using this plugin should prioritize applying updates to mitigate potential exposure.

CVE
CVE-2026-10627
Severity
MEDIUM
CVSS
5.3
EPSS
0.33%
WordPress

Original NVD Description

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view the titles, dates, descriptions, and location details of events and locations that administrators have marked as draft, pending, trashed, or private.