Loading market data...
← Back to CVE feed

CVE-2026-93661

LOW CVSS 2.7 View on NVD ↗

Description

The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any ticket on the site to their own event.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Published: Sep 24, 2026 06:17 UTC Modified: Sep 24, 2026 14:42 UTC