WordPress 中的 “The Events Manager – Calendar, Bookings, Tickets, and more!” 插件在 7.4.0 及以下所有版本中存在授权绕过漏洞。该漏洞是由于插件未正确验证用户是否有权执行特定操作所致。这使得未经身份验证的攻击者能够查看管理员标记为草稿、待审核、已删除或私密状态的事件标题、日期、描述以及地点详情。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| netweblogic | Events Manager – Calendar, Bookings, Tickets, and more! | 0 ~ 7.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14280 | 6.6 MEDIUM | Events Manager <= 7.3.7.4 - Authenticated (Administrator+) Local File Inclusion via 'dbem_ |
| CVE-2026-15023 | 6.5 MEDIUM | Events Manager <= 7.4.0 - Authenticated (Contributor+) SQL Injection via 'meta_key' Parame |
| CVE-2026-17089 | 6.1 MEDIUM | Events Manager <= 7.4.0.1 - Reflected Cross-Site Scripting via 'header_format' Parameter |
No comments yet