Vulnerability in WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce — CVE-2026-62041
MediumSeverity
—Estimated exploit probability
20,000+ sitesInstalls
Not publishedFixed in
What to do now
No fix has been published yet. Consider disabling WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce for now, or moving to an alternative.
Affected versions
- Everything up to and including 3.4.1
Affected: WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce (plugin, wp-event-manager)
What the vulnerability is
The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.4.1. This is due to a missing capability check on a function. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.