---
id: CVE-2025-7663
title: >-
  The Ovatheme Events Manager plugin for WordPress is vulnerable to unauthorized
  access due to a missing capability check on several functions in the
  /class-ovaem-ajax.php file in all versions up to, and including, 1.8.6
summary: >-
  The Ovatheme Events Manager plugin for WordPress is vulnerable to unauthorized
  access due to a missing capability check on several functions in the
  /class-ovaem-ajax.php file in all versions up to, and including, 1.8.6. This
  makes it pos…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-862
published: '2025-11-08'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-7663'
references:
  - url: >-
      https://themeforest.net/item/em4u-event-management-multipurpose-wordpress-theme/20846579
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/53f12e61-fdb0-4838-b733-fc4d7a4ff016?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00203
epssPercentile: 0.09397
ingestedAt: '2026-10-07T21:54:14.989Z'
---

## Overview

The Ovatheme Events Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the /class-ovaem-ajax.php file in all versions up to, and including, 1.8.6. This makes it possible for unauthenticated attackers to delete ticket files, download tickets, and more.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
