{"id":"CVE-2026-93661","title":"The Events Manager  WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any …","summary":"The Events Manager  WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any …","severity":"low","cvss":2.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-639"],"product":"Events Manager","affected":["events_manager < 7.4.5"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T11:17:03.613","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93661","references":[{"url":"https://wpscan.com/vulnerability/8f1c665e-15e4-4b5d-853d-919723614611/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-24T10:33:34.908014Z"},"ingestedAt":"2026-09-24T06:39:26.616Z","slug":"CVE-2026-93661","body":"## Overview\n\nThe Events Manager  WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any ticket on the site to their own event.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":15,"depthScoreParts":{"impact":14.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":210097,"id":"CVE-2026-93661","ts":1790250160764,"field":"cvss","old":null,"new":"2.7"},{"seq":210096,"id":"CVE-2026-93661","ts":1790250160764,"field":"severity","old":"none","new":"low"}]}