The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view the titles, dates, descriptions, and location details of events and locations that administrators have marked as draft, pending, trashed, or private.
We have discovered 24,735 live websites that are affected by CVE-2026-10627.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 24,735 live websites (70% of Events Manager for WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 106 versions ( 98% of all versions) |
| 6,305 websites | |
| 4,996 websites | |
| 1,964 websites | |
| 1,253 websites | |
| 1,227 websites | |
| 1,159 websites | |
| 696 websites | |
| 601 websites | |
| 562 websites | |
| 532 websites |
| .com | 6,095 websites |
| .de | 3,816 websites |
| .org | 3,302 websites |
| .nl | 1,166 websites |
| .fr | 985 websites |
| .it | 896 websites |
| .ch | 616 websites |
| .co.uk | 557 websites |
| .net | 510 websites |
| .at | 454 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **************.org | **,*** | ||
| ****.org | **,*** | ||
| *********.*******.org | **,*** | ||
| ********.org | **,*** | ||
| *****.br | **,*** | ||
| ****.org | **,*** | ||
| *****.org | **,*** | ||
| ***************.it | **,*** | ||
| ***********.*****.gov | **,*** | ||
| **********************.org | **,*** |
FAQ