{"api_version":"1","generated_at":"2026-08-25T03:48:41+00:00","cve":"CVE-2026-10627","urls":{"html":"https://cve.report/CVE-2026-10627","api":"https://cve.report/api/cve/CVE-2026-10627.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-10627","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-10627"},"summary":{"title":"Events Manager <= 7.4.0 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'status', 'private', and 'private_only' Parameters","description":"The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view the titles, dates, descriptions, and location details of events and locations that administrators have marked as draft, pending, trashed, or private.","state":"PUBLISHED","assigner":"Wordfence","published_at":"2026-08-25 03:16:54","updated_at":"2026-08-25 03:16:54"},"problem_types":["CWE-862","CWE-862 CWE-862 Missing Authorization"],"metrics":[{"version":"3.1","source":"security@wordfence.com","type":"Primary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.3.1/classes/em-object.php#L314","name":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.3.1/classes/em-object.php#L314","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0e52475e-2a04-4973-b419-fb477fe872e5?source=cve","name":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0e52475e-2a04-4973-b419-fb477fe872e5?source=cve","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/changeset?old_path=/events-manager/tags/7.4.0.1&new_path=/events-manager/tags/7.4.1","name":"https://plugins.trac.wordpress.org/changeset?old_path=/events-manager/tags/7.4.0.1&new_path=/events-manager/tags/7.4.1","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.2.3.1/classes/em-object.php#L314","name":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.2.3.1/classes/em-object.php#L314","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.3.1/em-actions.php#L823","name":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.3.1/em-actions.php#L823","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.2.3.1/classes/em-object.php#L1166","name":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.2.3.1/classes/em-object.php#L1166","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.3.1/classes/em-object.php#L1166","name":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.3.1/classes/em-object.php#L1166","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.3.1/em-actions.php#L906","name":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.3.1/em-actions.php#L906","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.2.3.1/em-actions.php#L823","name":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.2.3.1/em-actions.php#L823","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.2.3.1/em-actions.php#L906","name":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.2.3.1/em-actions.php#L906","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.2.3.1/classes/em-events.php#L654","name":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.2.3.1/classes/em-events.php#L654","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.3.1/classes/em-events.php#L654","name":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.3.1/classes/em-events.php#L654","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-10627","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10627","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"netweblogic","product":"Events Manager – Calendar, Bookings, Tickets, and more!","version":"affected 7.4.0 semver","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-06-02T14:27:27.000Z","lang":"en","value":"Vendor Notified"},{"source":"CNA","time":"2026-08-24T14:06:57.000Z","lang":"en","value":"Disclosed"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"molten bit","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Events Manager – Calendar, Bookings, Tickets, and more!","vendor":"netweblogic","versions":[{"lessThanOrEqual":"7.4.0","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"molten bit"}],"descriptions":[{"lang":"en","value":"The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view the titles, dates, descriptions, and location details of events and locations that administrators have marked as draft, pending, trashed, or private."}],"metrics":[{"cvssV3_1":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-862","description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-25T02:26:48.141Z","orgId":"b15e7b5b-3da4-40ae-a43c-f7aa60e62599","shortName":"Wordfence"},"references":[{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0e52475e-2a04-4973-b419-fb477fe872e5?source=cve"},{"url":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.3.1/classes/em-object.php#L314"},{"url":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.3.1/classes/em-object.php#L1166"},{"url":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.3.1/em-actions.php#L823"},{"url":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.3.1/em-actions.php#L906"},{"url":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.3.1/classes/em-events.php#L654"},{"url":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.2.3.1/classes/em-object.php#L314"},{"url":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.2.3.1/classes/em-object.php#L1166"},{"url":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.2.3.1/em-actions.php#L823"},{"url":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.2.3.1/em-actions.php#L906"},{"url":"https://plugins.trac.wordpress.org/browser/events-manager/tags/7.2.3.1/classes/em-events.php#L654"},{"url":"https://plugins.trac.wordpress.org/changeset?old_path=/events-manager/tags/7.4.0.1&new_path=/events-manager/tags/7.4.1"}],"timeline":[{"lang":"en","time":"2026-06-02T14:27:27.000Z","value":"Vendor Notified"},{"lang":"en","time":"2026-08-24T14:06:57.000Z","value":"Disclosed"}],"title":"Events Manager <= 7.4.0 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'status', 'private', and 'private_only' Parameters"}},"cveMetadata":{"assignerOrgId":"b15e7b5b-3da4-40ae-a43c-f7aa60e62599","assignerShortName":"Wordfence","cveId":"CVE-2026-10627","datePublished":"2026-08-25T02:26:48.141Z","dateReserved":"2026-06-02T14:12:18.517Z","dateUpdated":"2026-08-25T02:26:48.141Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-25 03:16:54","lastModifiedDate":"2026-08-25 03:16:54","problem_types":["CWE-862","CWE-862 CWE-862 Missing Authorization"],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"10627","Ordinal":"1","Title":"Events Manager <= 7.4.0 - Missing Authorization to Unauthenticat","CVE":"CVE-2026-10627","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"10627","Ordinal":"1","NoteData":"The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view the titles, dates, descriptions, and location details of events and locations that administrators have marked as draft, pending, trashed, or private.","Type":"Description","Title":"Events Manager <= 7.4.0 - Missing Authorization to Unauthenticat"}]}}}