{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/events-manager-7.1.0---7.4.0.x/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wp-event-manager:events_manager:7.1.0:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-18366"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Events Manager (7.1.0 - 7.4.0.x)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Events Manager WordPress plugin (versions 7.1.0 through 7.4.0.x) contains a critical privilege escalation vulnerability (CVE-2026-18366) stemming from an improperly implemented \u003ccode\u003emap_meta_cap\u003c/code\u003e filter. The vulnerability allows unauthenticated attackers to manipulate user accounts, including changing passwords and escalating roles to administrator, by exploiting the way the plugin handles capability checks for event and location post types.\u003c/p\u003e\n\u003cp\u003eWhen the WordPress REST API processes requests for users (e.g., \u003ccode\u003e/wp-json/wp/v2/users/{id}\u003c/code\u003e), it invokes the \u003ccode\u003emap_meta_cap\u003c/code\u003e filter. In the vulnerable versions, if the ID of the object being queried coincides with the ID of an event or location post, the plugin prematurely clears the required capabilities list. This results in the system incorrectly granting unauthorized access to sensitive operations like \u003ccode\u003eedit_user\u003c/code\u003e, \u003ccode\u003edelete_user\u003c/code\u003e, and \u003ccode\u003epromote_user\u003c/code\u003e. Attackers can force ID collisions via the plugin's guest booking feature to target specific users, making this a high-impact risk for WordPress sites utilizing the plugin.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site running Events Manager version 7.1.0 - 7.4.0.x with guest bookings enabled.\u003c/li\u003e\n\u003cli\u003eAttacker enumerates existing public event or location IDs to find target IDs or to prepare for a collision.\u003c/li\u003e\n\u003cli\u003eAttacker uses the \u003ccode\u003ewp_ajax_nopriv_booking_add\u003c/code\u003e endpoint to submit multiple guest bookings, causing the \u003ccode\u003ewp_users\u003c/code\u003e ID sequence to increment until it matches a targeted \u003ccode\u003eevent\u003c/code\u003e or \u003ccode\u003elocation\u003c/code\u003e post ID.\u003c/li\u003e\n\u003cli\u003eOnce a collision is achieved (or if a naturally occurring collision exists), the attacker targets the specific user ID via the REST API endpoint \u003ccode\u003e/wp-json/wp/v2/users/{id}\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe plugin's \u003ccode\u003emap_meta_cap\u003c/code\u003e filter incorrectly validates the request because the \u003ccode\u003euser_id\u003c/code\u003e matches an \u003ccode\u003eevent_id\u003c/code\u003e, clearing the required capability list.\u003c/li\u003e\n\u003cli\u003eAttacker sends a PUT request to the REST API to change the password of the account associated with the collided ID.\u003c/li\u003e\n\u003cli\u003eAttacker sends a secondary PUT request to promote the compromised account to the \u003ccode\u003eadministrator\u003c/code\u003e role.\u003c/li\u003e\n\u003cli\u003eAttacker logs into the WordPress administrative dashboard to gain full control of the site.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full administrative control over the affected WordPress installation. Given the CVSS 9.8 rating, this vulnerability poses a severe threat to site confidentiality, integrity, and availability. All sites using the vulnerable versions are susceptible to complete data exfiltration, defacement, or total site takeover by unauthenticated remote actors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately update the Events Manager plugin to version 7.4.1 or later.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to block unauthorized or suspicious requests to \u003ccode\u003e/wp-json/wp/v2/users/\u003c/code\u003e and \u003ccode\u003e/wp-admin/admin-ajax.php?action=booking_add\u003c/code\u003e originating from non-authenticated sources.\u003c/li\u003e\n\u003cli\u003eReview audit logs for unexpected account creation or role promotion events associated with the REST API.\u003c/li\u003e\n\u003cli\u003eRestrict access to administrative REST API endpoints to trusted IP addresses where possible.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-31T09:22:53Z","date_published":"2026-08-31T09:22:53Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-18366/","summary":"An unauthenticated privilege escalation vulnerability (CVE-2026-18366) in the Events Manager WordPress plugin allows attackers to compromise user accounts and escalate privileges via REST API exploitation.","title":"Unauthenticated Privilege Escalation in Events Manager Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-18366/"}],"language":"en","title":"CraftedSignal Threat Feed - Events Manager (7.1.0 - 7.4.0.x)","version":"https://jsonfeed.org/version/1.1"}