CVE-2026-18050 PUBLISHED

Events Manager < 7.4 - Unauthenticated Pending Upload Disclosure via events-manager/v1/uploads

Assigner: WPScan
Reserved: 28.07.2026 Published: 06.08.2026 Updated: 06.08.2026

The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve another user's in-progress upload when its temporary identifier is known. The identifier is high-entropy, is disclosed only to the uploader, and the file is removed on submission or by a scheduled cleanup, so a cross-user read is not achievable by guessing alone.

Product Status

Vendor Unknown
Product Events Manager
Versions Default: unaffected
  • affected from 0 to 7.4 (excl.)

Credits

  • Usama Arshad finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE