CVE-2026-18366 carries a CVSS 3.1 base score of 9.8 against Events Manager, a WordPress plugin published by Pixelite for managing bookable events and registrations. NVD classifies it as CWE-269 (Improper Privilege Management) and describes it as fixed in version 7.4.1, meaning all earlier versions are affected. VulnCheck’s KEV feed reports the CVE as exploited, dated August 31, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-18366 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description identifies an unusual failure mode: the plugin does not properly scope its own capability mapping, which has the effect of discarding access-control decisions WordPress itself already made for actions that have nothing to do with events management. The practical outcome, per NVD, is that an unauthenticated user can change the password of, escalate to Administrator, or delete any WordPress account whose user ID happens to match the ID of one of the plugin’s own posts.
That coincidental-ID mechanism is the core of what makes this bug unusual: it is not a credential check the plugin forgot, but a privilege-check design that conflates two unrelated ID spaces — WordPress user IDs and the plugin’s own post IDs — such that controlling or predicting the latter can grant control over the former. NVD does not describe additional preconditions beyond that ID collision.
Evidence and confidence
- Medium confidence — the CVSS 9.8 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE-269 classification, the fixed version (7.4.1), and the ID-collision mechanism all trace to NVD alone. The exploitation report traces to VulnCheck KEV alone. - Below-midpoint exploitation probability — FIRST’s EPSS model scores this CVE at 0.0039, a 32.7th percentile score as of our ingestion.
No field is in conflict between our two sources.
Why this matters
The vulnerability’s mechanism means exposure isn’t simply “is the plugin installed” — it depends on whether an attacker-reachable or attacker-influenceable post ID happens to collide with a privileged WordPress account’s user ID, a condition that will vary by site and isn’t something a site operator can easily audit for themselves without understanding the specific collision NVD describes. That opacity is itself a reason to treat this as urgent rather than assess likelihood site-by-site: the safer assumption is that any site running a pre-7.4.1 version is exposed, regardless of whether the operator can independently verify the ID-collision condition applies to their installation.
Because the fix is a straightforward version upgrade with a clearly stated boundary (7.4.1), this is a case where remediation is unambiguous even though the underlying mechanism is unusually specific.
Frequently Asked Questions
What is CVE-2026-18366? A CVSS 9.8 privilege escalation vulnerability (CWE-269) in the Events Manager WordPress plugin, fixed in version 7.4.1, that NVD states allows unauthenticated attackers to take over Administrator accounts under certain ID-collision conditions.
Is CVE-2026-18366 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 31, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration.
How does an attacker actually trigger this? NVD states the flaw is triggered when a WordPress user ID happens to match the ID of one of the plugin’s own posts — a capability-mapping failure that discards WordPress’s normal access-control checks for that user.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Which version fixes this? Version 7.4.1, per NVD.
Severity, vector, weakness classification, mechanism, and fixed version sourced from the National Vulnerability Database record for CVE-2026-18366. Exploitation status and the August 31, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.