plugin

Event Monster Vulnerabilities

17 known security issues reported for the Event Monster WordPress plugin. Most recent disclosed Jun 5, 2026.

4 high 4 medium

Running Event Monster on your site? Check whether your installed version is affected.

Scan your site free

Event Monster <= 2.1.0 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via em_capture_payment AJAX Action

medium

The Event Monster – Event Management, Events Calendar, Tickets plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 2.1.0. This is due to the capture_payment() AJAX handler (registered via wp_ajax_nopriv_em_capture_payment) trusting client-supplied payme...

CVSS:
5.3
Affected:
up to 2.1.0
Fixed in:
2.2.0
Disclosed:
Jun 5, 2026

CVE-2026-8608 on NVD →

Event monster <= 1.4.3 - Information Exposure Via Visitors List Export

medium

The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file is created in the wp-content folder with a hardcoded filename that is publicly acc...

CVSS:
5.3
Affected:
up to 1.4.3
Fixed in:
1.4.4
Disclosed:
Jan 13, 2025

CVE-2024-11396 on NVD →

Event Monster &#8211; Event Management, Tickets Booking, Upcoming Event [event-monster] < 1.4.4

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A WP Life Event Management Tickets Booking.This issue affects Event Management Tickets Booking: from n/a through 1.4.0.

Affected:
up to 1.4.4
Fixed in:
1.4.4
Disclosed:
Jun 21, 2024

CVE-2024-5059 on NVD →

Event Management Tickets Booking <= 1.4.3 - Unauthenticated Information Exposure

medium

The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.3. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 1.4.3
Fixed in:
1.4.4
Disclosed:
Jun 19, 2024

CVE-2024-5059 on NVD →

Event Monster &#8211; Event Management, Tickets Booking, Upcoming Event [event-monster] < 1.3.5

unknown

[en] The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.4 via deserialization via shortcode of untrusted input from a custom meta value. This makes it possible for authenticated attackers, with contri...

Affected:
up to 1.3.5
Fixed in:
1.3.5
Disclosed:
Apr 30, 2024

CVE-2024-1895 on NVD →

Event Monster <= 1.3.9 - Authenticated(Contributor+) PHP Object Injection via Custom Meta

high

The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.9 via deserialization via shortcode of untrusted input from a custom meta value. This makes it possible for authenticated attackers, with contributor...

CVSS:
7.5
Affected:
up to 1.3.9
Fixed in:
1.4.0
Disclosed:
Apr 29, 2024

CVE-2024-1895 on NVD →

Event Monster &#8211; Event Management, Tickets Booking, Upcoming Event [event-monster] <= 1.4.6 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Event Monster – Event Management, Tickets Booking, Upcoming Event allows Stored XSS.This issue affects Event Monster – Event Management, Tickets Booking, Upcoming Event: from n/a through 1.3.2.

Affected:
up to 1.4.6
Fix:
No patched version reported
Disclosed:
Dec 21, 2023

CVE-2023-47525 on NVD →

Event Management Tickets Booking <= 1.4.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings

medium

The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with admi...

CVSS:
4.4
Affected:
up to 1.4.6
Fixed in:
2.0.0
Disclosed:
Dec 19, 2023

CVE-2023-47525 on NVD →

Event Monster &#8211; Event Management, Tickets Booking, Upcoming Event [event-monster] < 1.2.0

unknown

[en] The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attackers to make logged in admin delete arbitrary visitors via a CSRF attack

Affected:
up to 1.2.0
Fixed in:
1.2.0
Disclosed:
Nov 21, 2022

CVE-2022-3336 on NVD →

Event Monster &#8211; Event Management, Tickets Booking, Upcoming Event [event-monster] < 1.2.1

unknown

[en] The Event Monster WordPress plugin before 1.2.0 does not validate and escape some parameters before using them in SQL statements, which could lead to SQL Injection exploitable by high privilege users

Affected:
up to 1.2.1
Fixed in:
1.2.1
Disclosed:
Nov 21, 2022

CVE-2022-3720 on NVD →

Event Monster <= 1.2.0 - Authenticated (Administrator+) SQL Injection

high

The Event Monster plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in versions up to, and including, 1.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with adminis...

CVSS:
7.2
Affected:
up to 1.2.0
Fixed in:
1.2.1
Disclosed:
Oct 31, 2022

CVE-2022-3720 on NVD →

Event Monster – Event Management, Tickets Booking, Upcoming Event <= 1.1.20 - Cross-Site Request Forgery

high

The Event Monster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.20. This is due to missing or incorrect nonce validation when processing AJAX actions. This makes it possible for unauthenticated attackers to invoke these actions and perform actions like deleting a...

CVSS:
8.8
Affected:
up to 1.1.20
Fixed in:
1.2.0
Disclosed:
Oct 27, 2022

CVE-2022-3336 on NVD →

Event Monster &#8211; Event Management, Tickets Booking, Upcoming Event [event-monster] < 1.0.6

unknown

Stored Cross-Site Scripting (XSS) vulnerability found by Admavidhya N in WordPress Event Management Tickets Booking plugin (versions <= 1.0.5).

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
May 27, 2019

Event Management Tickets Booking By Event Monster Plugin < 1.0.6 - Cross-Site Scripting

high

The Event Management Tickets Booking By Event Monster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...

CVSS:
7.2
Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
May 23, 2019

Event Monster &#8211; Event Management, Tickets Booking, Upcoming Event [event-monster] < 1.0.6

unknown

The Event Management Tickets Booking By Event Monster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
May 23, 2019

Event Monster &#8211; Event Management, Tickets Booking, Upcoming Event [event-monster] < 1.0.6

unknown

The Event Management Tickets Booking By Event Monster WordPress plugin was affected by a Stored XSS security vulnerability.

Affected:
up to 1.0.6
Fixed in:
1.0.6

Event Monster &#8211; Event Management, Tickets Booking, Upcoming Event [event-monster] < 1.4.4

unknown
Affected:
up to 1.4.4
Fixed in:
1.4.4

CVE-2024-11396 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database