Event Monster <= 2.1.0 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via em_capture_payment AJAX Action
medium
The Event Monster – Event Management, Events Calendar, Tickets plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 2.1.0. This is due to the capture_payment() AJAX handler (registered via wp_ajax_nopriv_em_capture_payment) trusting client-supplied payme...
- CVSS:
- 5.3
- Affected:
- up to 2.1.0
- Fixed in:
- 2.2.0
- Disclosed:
- Jun 5, 2026
CVE-2026-8608 on NVD →
Event monster <= 1.4.3 - Information Exposure Via Visitors List Export
medium
The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file is created in the wp-content folder with a hardcoded filename that is publicly acc...
- CVSS:
- 5.3
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.4
- Disclosed:
- Jan 13, 2025
CVE-2024-11396 on NVD →
Event Monster – Event Management, Tickets Booking, Upcoming Event [event-monster] < 1.4.4
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A WP Life Event Management Tickets Booking.This issue affects Event Management Tickets Booking: from n/a through 1.4.0.
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
- Disclosed:
- Jun 21, 2024
CVE-2024-5059 on NVD →
Event Management Tickets Booking <= 1.4.3 - Unauthenticated Information Exposure
medium
The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.3. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.4
- Disclosed:
- Jun 19, 2024
CVE-2024-5059 on NVD →
Event Monster – Event Management, Tickets Booking, Upcoming Event [event-monster] < 1.3.5
unknown
[en] The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.4 via deserialization via shortcode of untrusted input from a custom meta value. This makes it possible for authenticated attackers, with contri...
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.5
- Disclosed:
- Apr 30, 2024
CVE-2024-1895 on NVD →
Event Monster <= 1.3.9 - Authenticated(Contributor+) PHP Object Injection via Custom Meta
high
The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.9 via deserialization via shortcode of untrusted input from a custom meta value. This makes it possible for authenticated attackers, with contributor...
- CVSS:
- 7.5
- Affected:
- up to 1.3.9
- Fixed in:
- 1.4.0
- Disclosed:
- Apr 29, 2024
CVE-2024-1895 on NVD →
Event Monster – Event Management, Tickets Booking, Upcoming Event [event-monster] <= 1.4.6 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Event Monster – Event Management, Tickets Booking, Upcoming Event allows Stored XSS.This issue affects Event Monster – Event Management, Tickets Booking, Upcoming Event: from n/a through 1.3.2.
- Affected:
- up to 1.4.6
- Fix:
- No patched version reported
- Disclosed:
- Dec 21, 2023
CVE-2023-47525 on NVD →
Event Management Tickets Booking <= 1.4.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings
medium
The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with admi...
- CVSS:
- 4.4
- Affected:
- up to 1.4.6
- Fixed in:
- 2.0.0
- Disclosed:
- Dec 19, 2023
CVE-2023-47525 on NVD →
Event Monster – Event Management, Tickets Booking, Upcoming Event [event-monster] < 1.2.0
unknown
[en] The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attackers to make logged in admin delete arbitrary visitors via a CSRF attack
- Affected:
- up to 1.2.0
- Fixed in:
- 1.2.0
- Disclosed:
- Nov 21, 2022
CVE-2022-3336 on NVD →
Event Monster – Event Management, Tickets Booking, Upcoming Event [event-monster] < 1.2.1
unknown
[en] The Event Monster WordPress plugin before 1.2.0 does not validate and escape some parameters before using them in SQL statements, which could lead to SQL Injection exploitable by high privilege users
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.1
- Disclosed:
- Nov 21, 2022
CVE-2022-3720 on NVD →
Event Monster <= 1.2.0 - Authenticated (Administrator+) SQL Injection
high
The Event Monster plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in versions up to, and including, 1.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with adminis...
- CVSS:
- 7.2
- Affected:
- up to 1.2.0
- Fixed in:
- 1.2.1
- Disclosed:
- Oct 31, 2022
CVE-2022-3720 on NVD →
Event Monster – Event Management, Tickets Booking, Upcoming Event <= 1.1.20 - Cross-Site Request Forgery
high
The Event Monster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.20. This is due to missing or incorrect nonce validation when processing AJAX actions. This makes it possible for unauthenticated attackers to invoke these actions and perform actions like deleting a...
- CVSS:
- 8.8
- Affected:
- up to 1.1.20
- Fixed in:
- 1.2.0
- Disclosed:
- Oct 27, 2022
CVE-2022-3336 on NVD →
Event Monster – Event Management, Tickets Booking, Upcoming Event [event-monster] < 1.0.6
unknown
Stored Cross-Site Scripting (XSS) vulnerability found by Admavidhya N in WordPress Event Management Tickets Booking plugin (versions <= 1.0.5).
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- May 27, 2019
Event Management Tickets Booking By Event Monster Plugin < 1.0.6 - Cross-Site Scripting
high
The Event Management Tickets Booking By Event Monster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...
- CVSS:
- 7.2
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- May 23, 2019
Event Monster – Event Management, Tickets Booking, Upcoming Event [event-monster] < 1.0.6
unknown
The Event Management Tickets Booking By Event Monster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- May 23, 2019
Event Monster – Event Management, Tickets Booking, Upcoming Event [event-monster] < 1.0.6
unknown
The Event Management Tickets Booking By Event Monster WordPress plugin was affected by a Stored XSS security vulnerability.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
Event Monster – Event Management, Tickets Booking, Upcoming Event [event-monster] < 1.4.4
unknown
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
CVE-2024-11396 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database