PatchSiren

Events Manager CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Events Manager CVE published 2026-08-06

CVE-2026-18050

The Events Manager WordPress plugin before version 7.4 has a vulnerability that allows unauthenticated users to retrieve in-progress file uploads when the temporary identifier is known. This issue arises from the plugin's failure to perform authorization checks on a REST route serving temporary file uploads. The vulnerability has a CVSS score of 7.5 and is considered HIGH severity. Users of the plugin, es [truncated]