Sploitus

CVE-2026-18057

No indexed exploits for CVE-2026-18057 yet

The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing users with a subscriber account and above to perform SQL injection attacks and tamper with booking consent records belonging to other people.

Affected products
Events Manager
CVSS 3.1
8.1 HIGH
EPSS
0.2% (13th percentile)
Weakness
CWE-89
NVD status
Received
Published
2026-08-12
CVE-2026-18057 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-18057 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-18057 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.