CVE-2026-10627

Events Manager <= 7.4.0 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'status', 'private', and 'private_only' Parameters

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view the titles, dates, descriptions, and location details of events and locations that administrators have marked as draft, pending, trashed, or private.


We have discovered 24,735 live websites that are affected by CVE-2026-10627.

Run a Free Instant Scan




Affected Software

Product  Events Manager for WordPress
Category Wordpress Plugins
Vulnerable Domains24,735 live websites (70% of Events Manager for WordPress install base)
Vulnerable Versions
  • from 0 through 7.4
Vulnerable Versions Count106 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Aug 25, 2026
  • Updated - Aug 27, 2026

Credits

  • molten bit (finder)

Website Distribution by Country

Number of websites using CVE-2026-10627
United States6,305 websites



Germany4,996 websites
France1,964 websites
Netherlands1,253 websites
GB1,227 websites
Italy1,159 websites
Switzerland696 websites
Canada601 websites
Japan562 websites
Spain532 websites

Website Distribution by TLD

Number of websites using CVE-2026-10627
.com6,095 websites
.de3,816 websites
.org3,302 websites
.nl1,166 websites
.fr985 websites
.it896 websites
.ch616 websites
.co.uk557 websites
.net510 websites
.at454 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-10627

Top websites that are affected by CVE-2026-10627. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.org Switzerland**,***
****.org United States**,***
*********.*******.org United States**,***
********.org United States**,***
*****.br Brazil**,***
****.org France**,***
*****.org United States**,***
***************.it Italy**,***
***********.*****.gov United States**,***
**********************.org France**,***
See full domain list

FAQ

CVE-2026-10627 is Missing Authorization in Events Manager for WordPress
A total of 24,735 websites have been identified as vulnerable to CVE-2026-10627, based on global website indexing conducted by WebTechSurvey.
The Events Manager for WordPress is affected by the CVE-2026-10627 vulnerability.
Events Manager for WordPress versions up to and including 7.4 are vulnerable to CVE-2026-10627.

References