CVE-2026-18366
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
- Published
- Aug 12, 2026
- Updated
- Aug 12, 2026
- Assigning CNA
- WPScan
- Evidence observed
- Aug 24, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLow · next 30 days
- Percentile
- 32.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress already made for unrelated privileged actions, which allows unauthenticated users to change the password of, escalate to Administrator, or delete any account whose user ID happens to match the ID of one of the Events Manager WordPress plugin before 7.4.1's own posts.
Sources
4- CVE-2026-18366Exploit
Unauthenticated privilege-escalation PoC for WordPress Events Manager < 7.4.1; discovers colliding post/user IDs and escalates targets to administrator via REST or wp-admin.
- CVE-2026-18366Exploit
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
Exploit code for CVE-2026-18366, a proof-of-concept demonstrating the vulnerability.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.