Events Manager
by WordPress
Source repositories
CVEs (45)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-18366 | Cri | 0.64 | 9.8 | 0.01 | Aug 12, 2026 | The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress already made for unrelated privileged actions, which allows unauthenticated users to change the password of, escalate to… | ||
| CVE-2015-9298 | Cri | 0.64 | 9.8 | 0.02 | Aug 13, 2019 | The events-manager plugin before 5.6 for WordPress has code injection. | ||
| CVE-2026-18057 | Hig | 0.53 | 8.1 | 0.00 | Aug 12, 2026 | The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing users with a subscriber account and above to perform SQL injection attacks and tamper with booking consent records belonging to… | ||
| CVE-2026-18050 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2026 | The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve another user's in-progress upload when its temporary identifier is known. The… | ||
| CVE-2024-11260 | Hig | 0.49 | 7.5 | 0.01 | Feb 21, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient escaping on the user supplied parameter and lack of… | ||
| CVE-2020-35012 | Hig | 0.47 | 7.2 | 0.02 | Dec 1, 2021 | The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection | ||
| CVE-2026-66457 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager events-manager allows Reflected XSS.This issue affects Events Manager: from n/a through 7.4.2. | ||
| CVE-2025-6970 | Hig | 0.46 | 7.5 | 0.67 | Jul 9, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied parameter and lack of… | ||
| CVE-2023-48326 | Hig | 0.46 | 7.1 | 0.00 | Nov 30, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager allows Reflected XSS.This issue affects Events Manager: from n/a through 6.4.5. | ||
| CVE-2026-14280 | Med | 0.43 | 6.6 | 0.01 | Aug 25, 2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.3.7.4 via the em_options_save function. This makes it possible for authenticated attackers, with administrator-level… | ||
| CVE-2026-15023 | Med | 0.42 | 6.5 | 0.01 | Aug 25, 2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to generic SQL Injection via Stored 'meta_key' via Event/Location Duplicate Action in all versions up to, and including, 7.4.0 due to insufficient escaping on the user supplied… | ||
| CVE-2025-12976 | Med | 0.42 | 6.4 | 0.00 | Dec 18, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list_grouped' shortcode in all versions up to, and including, 7.2.2.1 due to insufficient input sanitization and output… | ||
| CVE-2024-2111 | Med | 0.42 | 6.4 | 0.00 | Mar 28, 2024 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the physical location value in all versions up to, and including, 6.4.7.1 due to insufficient input sanitization and output escaping. This makes it… | ||
| CVE-2026-17089 | Med | 0.40 | 6.1 | 0.00 | Aug 25, 2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'header_format' parameter in all versions up to, and including, 7.4.0.1 due to insufficient input sanitization and output escaping. This… | ||
| CVE-2020-35037 | Med | 0.40 | 6.1 | 0.01 | Dec 1, 2021 | The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues | ||
| CVE-2013-7480 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2019 | The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas. | ||
| CVE-2013-7479 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2019 | The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field. | ||
| CVE-2013-7478 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2019 | The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post. | ||
| CVE-2013-7477 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2019 | The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form. | ||
| CVE-2012-6716 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2019 | The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links. |
- risk 0.64cvss 9.8epss 0.01
The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress already made for unrelated privileged actions, which allows unauthenticated users to change the password of, escalate to…
- risk 0.64cvss 9.8epss 0.02
The events-manager plugin before 5.6 for WordPress has code injection.
- risk 0.53cvss 8.1epss 0.00
The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing users with a subscriber account and above to perform SQL injection attacks and tamper with booking consent records belonging to…
- risk 0.49cvss 7.5epss 0.00
The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve another user's in-progress upload when its temporary identifier is known. The…
- risk 0.49cvss 7.5epss 0.01
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient escaping on the user supplied parameter and lack of…
- risk 0.47cvss 7.2epss 0.02
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager events-manager allows Reflected XSS.This issue affects Events Manager: from n/a through 7.4.2.
- risk 0.46cvss 7.5epss 0.67
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied parameter and lack of…
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager allows Reflected XSS.This issue affects Events Manager: from n/a through 6.4.5.
- risk 0.43cvss 6.6epss 0.01
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.3.7.4 via the em_options_save function. This makes it possible for authenticated attackers, with administrator-level…
- risk 0.42cvss 6.5epss 0.01
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to generic SQL Injection via Stored 'meta_key' via Event/Location Duplicate Action in all versions up to, and including, 7.4.0 due to insufficient escaping on the user supplied…
- risk 0.42cvss 6.4epss 0.00
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list_grouped' shortcode in all versions up to, and including, 7.2.2.1 due to insufficient input sanitization and output…
- risk 0.42cvss 6.4epss 0.00
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the physical location value in all versions up to, and including, 6.4.7.1 due to insufficient input sanitization and output escaping. This makes it…
- risk 0.40cvss 6.1epss 0.00
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'header_format' parameter in all versions up to, and including, 7.4.0.1 due to insufficient input sanitization and output escaping. This…
- risk 0.40cvss 6.1epss 0.01
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues
- risk 0.40cvss 6.1epss 0.01
The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.
- risk 0.40cvss 6.1epss 0.01
The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.
- risk 0.40cvss 6.1epss 0.01
The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.
- risk 0.40cvss 6.1epss 0.01
The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.
- risk 0.40cvss 6.1epss 0.01
The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links.
Page 1 of 3