VYPR

Wp Event Solution

by WordPress

Source repositories

CVEs (10)

  • CVE-2025-68047HigJan 22, 2026
    risk 0.57cvss 8.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a through <= 4.1.3.

  • CVE-2025-49869HigAug 14, 2025
    risk 0.57cvss 8.8epss 0.00

    Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a through <= 4.0.31.

  • CVE-2026-75983HigSep 15, 2026
    risk 0.49cvss 7.5epss 0.01

    The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` function being registered as a…

  • CVE-2025-68045HigJun 16, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.

  • CVE-2026-28173HigAug 13, 2026
    risk 0.46cvss 7.1epss 0.00

    Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions.

  • CVE-2025-49321HigJun 27, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arraytics Eventin wp-event-solution allows Reflected XSS.This issue affects Eventin: from n/a through <= 4.0.28.

  • CVE-2026-82223MedSep 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions.

  • CVE-2026-28174MedAug 13, 2026
    risk 0.42cvss 6.5epss 0.00

    Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.

  • CVE-2026-66451MedAug 6, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions.

  • CVE-2026-15398MedSep 9, 2026
    risk 0.28cvss 4.3epss 0.00

    The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.22. This is due to the plugin not properly verifying that a user is authorized to perform an…