CVE-2026-18366 is an access control vulnerability in the Events Manager plugin for WordPress affecting versions prior to 7.4.1. The plugin does not properly scope its capability mapping and can override or discard authorization decisions already made by WordPress for unrelated privileged actions. As a result, authorization checks can be incorrectly satisfied when operating on user accounts whose numeric user ID matches the ID of one of the plugin's posts. This logic flaw enables unauthenticated attackers to perform privileged account-management actions against affected accounts.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
The repository consists of one 45,538-byte Python program, `CVE-2026-18366.py`, and is not associated with a recognized exploit framework. It is an asynchronous, multi-target exploit tool accepting either one URL (`-u`) or a target list (`-l`), with configurable worker count and request timeout. It normalizes WordPress URLs, probes Events Manager plugin files for version evidence, crawls public event/location pages, extracts event IDs, booking forms, ticket fields, nonces, post IDs, and author/user indicators, and queries several WordPress REST API route variants. The stated target is Events Manager before 7.4.1, tracked as CVE-2026-18366. Constants and completion statistics indicate a chained workflow: identify vulnerable installations, attempt unauthenticated privilege escalation/account takeover, authenticate using a fixed password, check for WordPress administrator access, then use plugin-install/upload functionality to deploy a shell-bearing plugin ZIP. Results are recorded in a local `adminS.txt` file. The embedded password and plugin-upload shell behavior make this an operational compromise tool rather than a detection-only PoC.
This repository is a compact exploit package centered on a single Python script, CVE-2026-18366.py, plus a README and license. The exploit targets a privilege-escalation flaw in the WordPress Events Manager plugin before 7.4.1. According to the code comments and README, the bug is caused by incorrect capability mapping in EM\Archetypes::map_meta_cap, allowing unauthenticated requests to WordPress core REST user endpoints to succeed when the chosen user ID collides with an Events Manager event/location post ID. Repository structure: 3 files total, with 1 code file. The Python script is the operational entry point and uses asyncio plus aiohttp for concurrent multi-target exploitation. The README documents usage, attack flow, and expected output. The script accepts a target list and worker count, normalizes URLs, processes many hosts concurrently, and writes successful results to adminS.txt. Main exploit capabilities observed from code/comments and repository documentation: - Detects Events Manager plugin presence/version using known plugin files under /wp-content/plugins/events-manager/. - Enumerates candidate event/location post IDs from public pages, feeds, and WordPress REST endpoints. - Attempts unauthenticated privilege escalation by sending JSON updates to /wp-json/wp/v2/users/{id} and equivalent rest_route variants, setting a known password and administrator role. - Supports an alternate guest-booking path to create users until a user ID collides with an event/location post ID, leveraging public booking forms/nonces when anonymous bookings are enabled. - Performs username/author enumeration and login verification after exploitation. - README indicates post-exploitation shell upload via plugin/theme mechanisms once admin access is obtained. This is not merely a detector: it is an operational exploit with automated targeting, exploitation, credential setting, result logging, and documented post-compromise actions. The attack vector is remote web/network exploitation against exposed WordPress sites.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.