plugin

Event Post Vulnerabilities

23 known security issues reported for the Event Post WordPress plugin. Most recent disclosed Jul 22, 2026.

1 critical 11 medium

Running Event Post on your site? Check whether your installed version is affected.

Scan your site free

Event Post <= 6.1.0 - Missing Authorization

medium

The Event Post plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.1.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 6.1.0
Fixed in:
6.1.1
Disclosed:
Jul 22, 2026

CVE-2026-65486 on NVD →

Event post [event-post] <= 5.10.3 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post event-post.This issue affects Event post: from n/a through <= 5.10.3.

Affected:
up to 5.10.3
Fix:
No patched version reported
Disclosed:
Oct 22, 2025

CVE-2025-62042 on NVD →

Event post <= 5.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
6.4
Affected:
up to 5.10.3
Fixed in:
5.10.4
Disclosed:
Oct 16, 2025

CVE-2025-62042 on NVD →

Event post [event-post] < 5.10.2

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post allows Stored XSS. This issue affects Event post: from n/a through 5.10.1.

Affected:
up to 5.10.2
Fixed in:
5.10.2
Disclosed:
Jun 6, 2025

CVE-2025-49298 on NVD →

Event post <= 5.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
6.4
Affected:
up to 5.10.1
Fixed in:
5.10.2
Disclosed:
Jun 5, 2025

CVE-2025-49298 on NVD →

Event post <= 5.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.9.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
6.4
Affected:
up to 5.9.11
Fixed in:
5.10.0
Disclosed:
Apr 22, 2025

CVE-2025-46228 on NVD →

Event post [event-post] < 5.10.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post allows DOM-Based XSS. This issue affects Event post: from n/a through 5.9.11.

Affected:
up to 5.10.0
Fixed in:
5.10.0
Disclosed:
Apr 22, 2025

CVE-2025-46228 on NVD →

Event post [event-post] < 5.9.9

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post allows Stored XSS.This issue affects Event post: from n/a through 5.9.8.

Affected:
up to 5.9.9
Fixed in:
5.9.9
Disclosed:
Mar 26, 2025

CVE-2025-26923 on NVD →

Event post <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list' shortcodes in all versions up to, and including, 5.9.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...

CVSS:
5.4
Affected:
up to 5.9.9
Fixed in:
5.9.10
Disclosed:
Mar 25, 2025

CVE-2025-2167 on NVD →

Event post <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
6.4
Affected:
up to 5.9.8
Fixed in:
5.9.9
Disclosed:
Mar 11, 2025

CVE-2025-26923 on NVD →

Event post <= 5.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
6.4
Affected:
up to 5.9.7
Fixed in:
5.9.8
Disclosed:
Jan 24, 2025

CVE-2025-24585 on NVD →

Event post [event-post] < 5.9.8

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N.O.U.S. Open Useful and Simple Event post allows Stored XSS. This issue affects Event post: from n/a through 5.9.7.

Affected:
up to 5.9.8
Fixed in:
5.9.8
Disclosed:
Jan 24, 2025

CVE-2025-24585 on NVD →

Event post [event-post] < 5.9.7

unknown

[en] The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's events_cal shortcode in all versions up to, and including, 5.9.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contrib...

Affected:
up to 5.9.7
Fixed in:
5.9.7
Disclosed:
Nov 6, 2024

CVE-2024-10186 on NVD →

Event Post <= 5.9.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via events_cal Shortcode

medium

The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's events_cal shortcode in all versions up to, and including, 5.9.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-...

CVSS:
6.4
Affected:
up to 5.9.6
Fixed in:
5.9.7
Disclosed:
Nov 5, 2024

CVE-2024-10186 on NVD →

Event post [event-post] <= 5.9.10 (unfixed)

unknown

[en] The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing nonce check on the save_bulkdatas function in all versions up to, and including, 5.9.5. This makes it possible for unauthenticated attackers to update post_meta_data via a forged request, granted they can trick...

Affected:
up to 5.9.10
Fix:
No patched version reported
Disclosed:
Jul 12, 2024

CVE-2024-1375 on NVD →

Event post [event-post] < 5.9.6

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in N.O.U.S. Open Useful and Simple Event post allows PHP Local File Inclusion.This issue affects Event post: from n/a through 5.9.5.

Affected:
up to 5.9.6
Fixed in:
5.9.6
Disclosed:
Jul 12, 2024

CVE-2024-38735 on NVD →

Event post <= 5.9.5 - Unauthenticated Local File Inclusion

critical

The Event post plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.9.5 via the generate_ics() function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This ca...

CVSS:
9.8
Affected:
up to 5.9.5
Fixed in:
5.9.6
Disclosed:
Jul 11, 2024

CVE-2024-38735 on NVD →

Event post <= 5.9.10 - Cross-Site Request Forgery

medium

The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing nonce check on the save_bulkdatas function in all versions up to, and including, 5.9.10. This makes it possible for unauthenticated attackers to update post_meta_data via a forged request, granted they can trick a lo...

CVSS:
4.3
Affected:
up to 5.9.10
Fix:
No patched version reported
Disclosed:
Jul 11, 2024

CVE-2024-1375 on NVD →

Event post [event-post] < 5.9.5

unknown

[en] The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing capability check on the save_bulkdatas function in all versions up to, and including, 5.9.4. This makes it possible for authenticated attackers, with subscriber access or higher, to update post_meta_data.

Affected:
up to 5.9.5
Fixed in:
5.9.5
Disclosed:
May 24, 2024

CVE-2024-1376 on NVD →

Event post <= 5.9.4 - Missing Authorization

medium

The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing capability check on the save_bulkdatas function in all versions up to, and including, 5.9.4. This makes it possible for authenticated attackers, with subscriber access or higher, to update post_meta_data.

CVSS:
4.3
Affected:
up to 5.9.4
Fixed in:
5.9.5
Disclosed:
May 23, 2024

CVE-2024-1376 on NVD →

Event post [event-post] < 5.9.1

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N.O.U.S. Open Useful and Simple Event post allows Stored XSS.This issue affects Event post: from n/a through 5.8.6.

Affected:
up to 5.9.1
Fixed in:
5.9.1
Disclosed:
Dec 15, 2023

CVE-2023-49179 on NVD →

Event post <= 5.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

medium

The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 5.9.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and...

CVSS:
6.4
Affected:
up to 5.9.0
Fixed in:
5.9.1
Disclosed:
Nov 29, 2023

CVE-2023-49179 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database