Skip to main content
Vulnerability Database/CVE-2026-93662

CVE-2026-93662: Events Manager WordPress Information Leak

CVE-2026-93662 is an information disclosure flaw in Events Manager WordPress plugin that lets low-privileged users access unpublished events and venue addresses from other accounts. This post covers technical details, impact, and mitigation.

Published:

CVE-2026-93662 Overview

CVE-2026-93662 is an information disclosure vulnerability in the Events Manager WordPress plugin before version 7.4.5. The plugin fails to enforce ownership scope on logged-in event and location search operations. When a caller supplies a custom owner value, the plugin honors it without verifying that the requester owns the referenced content. A low-privileged authenticated user can retrieve other accounts' unpublished, pending, or trashed events and venues, including full street addresses. The weakness is classified as [CWE-200] Exposure of Sensitive Information to an Unauthorized Actor.

Critical Impact

Authenticated users with minimal privileges can enumerate private event and venue data belonging to other site accounts, exposing draft content and physical addresses.

Affected Products

  • Events Manager WordPress plugin versions prior to 7.4.5
  • WordPress sites permitting subscriber or contributor-level registration with the plugin installed
  • Multi-author or membership WordPress deployments using Events Manager for private event management

Discovery Timeline

  • 2026-09-24 - CVE-2026-93662 published to the National Vulnerability Database
  • 2026-09-24 - Last updated in NVD database

Technical Details for CVE-2026-93662

Vulnerability Analysis

The Events Manager plugin exposes a logged-in search interface for events and locations. This interface is intended to return only content owned by the requesting user. The plugin builds its query using an owner parameter supplied by the client. It fails to override or validate that value against the current user's identity. An authenticated attacker can substitute another user's identifier and receive that user's private records.

The returned records include unpublished, pending review, and trashed items. They also include venue data containing full street addresses. This defeats the intended access boundary between authors on multi-user WordPress sites.

Root Cause

The root cause is missing authorization enforcement on a user-supplied query parameter. The plugin treats the owner value as trusted input rather than deriving it server-side from the authenticated session. According to the WPScan Vulnerability Analysis, the scope filter is not forced when the caller submits its own owner value.

Attack Vector

Exploitation requires an authenticated account with low privileges, such as a subscriber on sites where registration is open. The attacker issues the plugin's logged-in search request and sets the owner parameter to a target user's ID. The server returns event and venue records belonging to that user, including drafts and trashed items with full location data. No user interaction from the victim is required, and the attack can be automated to enumerate every author on the site.

See the WPScan Vulnerability Analysis for the technical breakdown of the affected search handler.

Detection Methods for CVE-2026-93662

Indicators of Compromise

  • Authenticated HTTP requests to Events Manager search endpoints containing an owner parameter that does not match the session user ID
  • Repeated requests from a single low-privileged account iterating through sequential owner values
  • Unexpected access to draft, pending, or trashed event content by non-editor accounts

Detection Strategies

  • Review WordPress access logs for POST or GET requests to Events Manager AJAX or REST endpoints containing an owner query parameter
  • Correlate authenticated session user IDs with the owner values submitted in event and location search requests
  • Alert on subscriber-level accounts issuing large volumes of event or location search queries in short windows

Monitoring Recommendations

  • Enable WordPress audit logging with request parameter capture to preserve owner values submitted to plugin endpoints
  • Forward web server and WordPress logs to a centralized SIEM or data lake for cross-account correlation
  • Monitor for anomalous read access patterns targeting event post types (event) and location taxonomies

How to Mitigate CVE-2026-93662

Immediate Actions Required

  • Upgrade the Events Manager plugin to version 7.4.5 or later on all WordPress installations
  • Audit existing user accounts and remove unused low-privileged accounts that could be leveraged for enumeration
  • Review recent access logs for suspicious owner parameter manipulation and identify potentially exposed content

Patch Information

The vendor addressed the flaw in Events Manager 7.4.5 by enforcing the authenticated user's identity as the scope for logged-in event and location searches. Refer to the WPScan Vulnerability Analysis for confirmation of the fixed version.

Workarounds

  • Disable open user registration on affected WordPress sites until the plugin is upgraded
  • Restrict access to the Events Manager plugin's search endpoints using a web application firewall rule that strips or validates the owner parameter
  • Temporarily remove or unpublish sensitive venue records containing physical addresses until patching is complete
bash
# Example WP-CLI upgrade to remediate CVE-2026-93662
wp plugin update events-manager --version=7.4.5
wp plugin list --name=events-manager --fields=name,status,version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.