Events Manager
by WordPress
Source repositories
CVEs (38)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-18366 | Cri | 0.64 | 9.8 | 0.00 | Aug 12, 2026 | The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress already made for unrelated privileged actions, which allows unauthenticated users to change the password of, escalate to… | ||
| CVE-2015-9298 | Cri | 0.64 | 9.8 | 0.02 | Aug 13, 2019 | The events-manager plugin before 5.6 for WordPress has code injection. | ||
| CVE-2026-18057 | Hig | 0.53 | 8.1 | 0.00 | Aug 12, 2026 | The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing users with a subscriber account and above to perform SQL injection attacks and tamper with booking consent records belonging to… | ||
| CVE-2026-18050 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2026 | The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve another user's in-progress upload when its temporary identifier is known. The… | ||
| CVE-2024-11260 | Hig | 0.49 | 7.5 | 0.01 | Feb 21, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient escaping on the user supplied parameter and lack of… | ||
| CVE-2020-35012 | Hig | 0.47 | 7.2 | 0.01 | Dec 1, 2021 | The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection | ||
| CVE-2026-66457 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions. | ||
| CVE-2025-6970 | Hig | 0.46 | 7.5 | 0.57 | Jul 9, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied parameter and lack of… | ||
| CVE-2023-48326 | Hig | 0.46 | 7.1 | 0.00 | Nov 30, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager allows Reflected XSS.This issue affects Events Manager: from n/a through 6.4.5. | ||
| CVE-2025-12976 | Med | 0.42 | 6.4 | 0.00 | Dec 18, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list_grouped' shortcode in all versions up to, and including, 7.2.2.1 due to insufficient input sanitization and output… | ||
| CVE-2024-2111 | Med | 0.42 | 6.4 | 0.00 | Mar 28, 2024 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the physical location value in all versions up to, and including, 6.4.7.1 due to insufficient input sanitization and output escaping. This makes it… | ||
| CVE-2020-35037 | Med | 0.40 | 6.1 | 0.01 | Dec 1, 2021 | The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues | ||
| CVE-2013-7480 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2019 | The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas. | ||
| CVE-2013-7479 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2019 | The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field. | ||
| CVE-2013-7478 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2019 | The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post. | ||
| CVE-2013-7477 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2019 | The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form. | ||
| CVE-2012-6716 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2019 | The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links. | ||
| CVE-2015-9300 | Med | 0.40 | 6.1 | 0.01 | Aug 13, 2019 | The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues. | ||
| CVE-2015-9299 | Med | 0.40 | 6.1 | 0.01 | Aug 13, 2019 | The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS. | ||
| CVE-2015-9297 | Med | 0.40 | 6.1 | 0.01 | Aug 13, 2019 | The events-manager plugin before 5.6 for WordPress has XSS. |
- risk 0.64cvss 9.8epss 0.00
The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress already made for unrelated privileged actions, which allows unauthenticated users to change the password of, escalate to…
- risk 0.64cvss 9.8epss 0.02
The events-manager plugin before 5.6 for WordPress has code injection.
- risk 0.53cvss 8.1epss 0.00
The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing users with a subscriber account and above to perform SQL injection attacks and tamper with booking consent records belonging to…
- risk 0.49cvss 7.5epss 0.00
The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve another user's in-progress upload when its temporary identifier is known. The…
- risk 0.49cvss 7.5epss 0.01
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient escaping on the user supplied parameter and lack of…
- risk 0.47cvss 7.2epss 0.01
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions.
- risk 0.46cvss 7.5epss 0.57
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied parameter and lack of…
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager allows Reflected XSS.This issue affects Events Manager: from n/a through 6.4.5.
- risk 0.42cvss 6.4epss 0.00
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list_grouped' shortcode in all versions up to, and including, 7.2.2.1 due to insufficient input sanitization and output…
- risk 0.42cvss 6.4epss 0.00
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the physical location value in all versions up to, and including, 6.4.7.1 due to insufficient input sanitization and output escaping. This makes it…
- risk 0.40cvss 6.1epss 0.01
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues
- risk 0.40cvss 6.1epss 0.01
The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.
- risk 0.40cvss 6.1epss 0.01
The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.
- risk 0.40cvss 6.1epss 0.01
The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.
- risk 0.40cvss 6.1epss 0.01
The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.
- risk 0.40cvss 6.1epss 0.01
The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links.
- risk 0.40cvss 6.1epss 0.01
The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues.
- risk 0.40cvss 6.1epss 0.01
The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS.
- risk 0.40cvss 6.1epss 0.01
The events-manager plugin before 5.6 for WordPress has XSS.
Page 1 of 2