The Events Manager 是一款 WordPress 插件,在版本 7.4.5 之前存在一个安全漏洞。该漏洞允许通过篡改票据更新请求,替换原本授权的票据标识符。具体来说,攻击者可以利用此漏洞,通过管理某个活动(event)的票据,将任意其他活动的票据覆盖并重新分配到自己控制的活动中。 翻译: 在 The Events Manager 这款 WordPress 插件中,7.4.5 版本之前存在一个漏洞,该漏洞未能阻止票据更新请求替换其被授权操作的目标票据标识符。这导致任何能够管理某个活动票据的用户,可以将
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Events Manager | 0 ~ 7.4.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93662 | Events Manager 7.4.1 - 7.4.4 - Subscriber+ Unpublished Event and Location Disclosure via ' | |
| CVE-2026-88847 | MasterStudy LMS < 3.7.50 - Subscriber+ Lesson Completion Record Creation | |
| CVE-2026-89004 | WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Campaign Configuration and Log Disclosu | |
| CVE-2026-89005 | WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Word to Category | |
| CVE-2026-89002 | WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Campaign Item Preview | |
| CVE-2026-88843 | MasterStudy LMS 3.5.29 - < 3.7.50 - Contributor+ LFI via Elementor Courses Categories Widg | |
| CVE-2026-88846 | MasterStudy LMS 2.3.0 - < 3.7.50 - Unauthenticated Account Creation with Registration Disa | |
| CVE-2026-88845 | MasterStudy LMS 2.3.0 - < 3.7.50 - Subscriber+ Course and Lesson Creation via Demo Import | |
| CVE-2026-82195 | 10Web Booster < 2.34.0 - Unauthenticated Connection Secret Disclosure and Deletion | |
| CVE-2026-82850 | Masteriyo LMS < 3.4.2 - Subscriber+ Quiz Answer Key Disclosure | |
| CVE-2026-82849 | Masteriyo LMS < 3.4.2 - Subscriber+ Arbitrary User Course Progress Disclosure via IDOR | |
| CVE-2026-84151 | The Post Grid < 7.9.5 - Contributor+ Stored HTML/iframe Injection via wp_kses_post Allow-L | |
| CVE-2026-74991 | WPForms Lite 1.8.8.2 - 2.0.1.1 - Unauthenticated Stripe Refund and Subscription Cancellati | |
| CVE-2026-80338 | CMB2 < 2.13.0 - Subscriber+ Arbitrary Option Corruption via oEmbed Handler | |
| CVE-2026-80513 | wpForo Forum < 3.1.6 - Subscriber+ PHP Object Injection via Profile Fields |
No comments yet