Wp Event Solution
by WordPress
Source repositories
CVEs (10)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-68047 | Hig | 0.57 | 8.8 | 0.01 | Jan 22, 2026 | Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a through <= 4.1.3. | ||
| CVE-2025-49869 | Hig | 0.57 | 8.8 | 0.00 | Aug 14, 2025 | Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a through <= 4.0.31. | ||
| CVE-2026-75983 | Hig | 0.49 | 7.5 | 0.01 | Sep 15, 2026 | The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` function being registered as a… | ||
| CVE-2025-68045 | Hig | 0.49 | 7.5 | 0.00 | Jun 16, 2026 | Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions. | ||
| CVE-2026-28173 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2026 | Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions. | ||
| CVE-2025-49321 | Hig | 0.46 | 7.1 | 0.00 | Jun 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arraytics Eventin wp-event-solution allows Reflected XSS.This issue affects Eventin: from n/a through <= 4.0.28. | ||
| CVE-2026-82223 | Med | 0.42 | 6.5 | 0.00 | Sep 2, 2026 | Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions. | ||
| CVE-2026-28174 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions. | ||
| CVE-2026-66451 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2026 | Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions. | ||
| CVE-2026-15398 | Med | 0.28 | 4.3 | 0.00 | Sep 9, 2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.22. This is due to the plugin not properly verifying that a user is authorized to perform an… |
- risk 0.57cvss 8.8epss 0.01
Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a through <= 4.1.3.
- risk 0.57cvss 8.8epss 0.00
Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a through <= 4.0.31.
- risk 0.49cvss 7.5epss 0.01
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` function being registered as a…
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.
- risk 0.46cvss 7.1epss 0.00
Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arraytics Eventin wp-event-solution allows Reflected XSS.This issue affects Eventin: from n/a through <= 4.0.28.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions.
- risk 0.42cvss 6.5epss 0.00
Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions.
- risk 0.28cvss 4.3epss 0.00
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.22. This is due to the plugin not properly verifying that a user is authorized to perform an…