VYPR

Events Made Easy

by WordPress

CVEs (10)

  • CVE-2022-1905CriJun 20, 2022
    risk 0.67cvss 9.8epss 0.38

    The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

  • CVE-2023-28660HigMar 22, 2023
    risk 0.57cvss 8.8epss 0.01

    The Events Made Easy WordPress Plugin, version <= 2.3.14 is affected by an authenticated SQL injection vulnerability in the 'search_name' parameter in the eme_recurrences_list action.

  • CVE-2021-25030HigJan 3, 2022
    risk 0.57cvss 8.8epss 0.02

    The Events Made Easy WordPress plugin before 2.2.36 does not sanitise and escape the search_text parameter before using it in a SQL statement via the eme_searchmail AJAX action, available to any authenticated users. As a result, users with a role as low as subscriber can call it…

  • CVE-2026-75963HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.01

    The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include…

  • CVE-2026-28162HigAug 24, 2026
    risk 0.46cvss 7.1epss

    Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.

  • CVE-2023-0404MedJan 19, 2023
    risk 0.35cvss 5.4epss 0.01

    The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions related to AJAX actions in versions up to, and including, 2.3.16. This makes it possible for authenticated attackers, with subscriber-level…

  • CVE-2026-14842MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauthenticated attackers to pay a low amount for a cheap booking and have a separate, higher-priced booking marked as fully paid.

  • CVE-2021-24813MedNov 1, 2021
    risk 0.31cvss 4.8epss 0.01

    The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

  • CVE-2026-14843MedJul 31, 2026
    risk 0.00cvss 5.3epss 0.00

    The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated data-change request, relying only on a public nonce with no per-record token or ownership check, allowing…

  • CVE-2026-59557MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.