WP Security CheckVulnerability data as of October 10, 2026

Vulnerability alerts / October 9, 2026

Vulnerability in WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce — CVE-2026-62041

MediumSeverity
CVSS 4.3
—Estimated exploit probability
EPSS
20,000+ sitesInstalls
Not publishedFixed in

What to do now

No fix has been published yet. Consider disabling WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce for now, or moving to an alternative.

Affected versions

  • Everything up to and including 3.4.1

Affected: WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce (plugin, wp-event-manager)

Check: The plugin on wordpress.org / Our record for WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce

What the vulnerability is

The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.4.1. This is due to a missing capability check on a function. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

This description is reproduced verbatim from the public vulnerability record.

Sources

Part of this record comes from Wordfence Intelligence. Original: https://www.wordfence.com/threat-intel/vulnerabilities/id/7009e69d-36b1-46a1-9be6-74f19fb19303
Copyright 2012-2026 Defiant Inc. / Full license text

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts