CVE-2026-93662 Overview
CVE-2026-93662 is an information disclosure vulnerability in the Events Manager WordPress plugin before version 7.4.5. The plugin fails to enforce ownership scope on logged-in event and location search operations. When a caller supplies a custom owner value, the plugin honors it without verifying that the requester owns the referenced content. A low-privileged authenticated user can retrieve other accounts' unpublished, pending, or trashed events and venues, including full street addresses. The weakness is classified as [CWE-200] Exposure of Sensitive Information to an Unauthorized Actor.
Critical Impact
Authenticated users with minimal privileges can enumerate private event and venue data belonging to other site accounts, exposing draft content and physical addresses.
Affected Products
- Events Manager WordPress plugin versions prior to 7.4.5
- WordPress sites permitting subscriber or contributor-level registration with the plugin installed
- Multi-author or membership WordPress deployments using Events Manager for private event management
Discovery Timeline
- 2026-09-24 - CVE-2026-93662 published to the National Vulnerability Database
- 2026-09-24 - Last updated in NVD database
Technical Details for CVE-2026-93662
Vulnerability Analysis
The Events Manager plugin exposes a logged-in search interface for events and locations. This interface is intended to return only content owned by the requesting user. The plugin builds its query using an owner parameter supplied by the client. It fails to override or validate that value against the current user's identity. An authenticated attacker can substitute another user's identifier and receive that user's private records.
The returned records include unpublished, pending review, and trashed items. They also include venue data containing full street addresses. This defeats the intended access boundary between authors on multi-user WordPress sites.
Root Cause
The root cause is missing authorization enforcement on a user-supplied query parameter. The plugin treats the owner value as trusted input rather than deriving it server-side from the authenticated session. According to the WPScan Vulnerability Analysis, the scope filter is not forced when the caller submits its own owner value.
Attack Vector
Exploitation requires an authenticated account with low privileges, such as a subscriber on sites where registration is open. The attacker issues the plugin's logged-in search request and sets the owner parameter to a target user's ID. The server returns event and venue records belonging to that user, including drafts and trashed items with full location data. No user interaction from the victim is required, and the attack can be automated to enumerate every author on the site.
See the WPScan Vulnerability Analysis for the technical breakdown of the affected search handler.
Detection Methods for CVE-2026-93662
Indicators of Compromise
- Authenticated HTTP requests to Events Manager search endpoints containing an owner parameter that does not match the session user ID
- Repeated requests from a single low-privileged account iterating through sequential owner values
- Unexpected access to draft, pending, or trashed event content by non-editor accounts
Detection Strategies
- Review WordPress access logs for POST or GET requests to Events Manager AJAX or REST endpoints containing an owner query parameter
- Correlate authenticated session user IDs with the owner values submitted in event and location search requests
- Alert on subscriber-level accounts issuing large volumes of event or location search queries in short windows
Monitoring Recommendations
- Enable WordPress audit logging with request parameter capture to preserve owner values submitted to plugin endpoints
- Forward web server and WordPress logs to a centralized SIEM or data lake for cross-account correlation
- Monitor for anomalous read access patterns targeting event post types (event) and location taxonomies
How to Mitigate CVE-2026-93662
Immediate Actions Required
- Upgrade the Events Manager plugin to version 7.4.5 or later on all WordPress installations
- Audit existing user accounts and remove unused low-privileged accounts that could be leveraged for enumeration
- Review recent access logs for suspicious owner parameter manipulation and identify potentially exposed content
Patch Information
The vendor addressed the flaw in Events Manager 7.4.5 by enforcing the authenticated user's identity as the scope for logged-in event and location searches. Refer to the WPScan Vulnerability Analysis for confirmation of the fixed version.
Workarounds
- Disable open user registration on affected WordPress sites until the plugin is upgraded
- Restrict access to the Events Manager plugin's search endpoints using a web application firewall rule that strips or validates the owner parameter
- Temporarily remove or unpublish sensitive venue records containing physical addresses until patching is complete
# Example WP-CLI upgrade to remediate CVE-2026-93662
wp plugin update events-manager --version=7.4.5
wp plugin list --name=events-manager --fields=name,status,version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
