EventPrime <= 4.3.4.2 - Unauthenticated Stored Cross-Site Scripting via 'new_event_type_background_color' Parameter
high
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_event_type_background_color' parameter in all versions up to, and including, 4.3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...
- CVSS:
- 7.2
- Affected:
- up to 4.3.4.2
- Fixed in:
- 4.3.4.3
- Disclosed:
- Jul 8, 2026
CVE-2026-13441 on NVD →
EventPrime – Events Calendar, Bookings and Tickets <= 4.3.4.1 - Authenticated (Subscriber+) PHP Object Injection
high
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.3.4.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known...
- CVSS:
- 7.5
- Affected:
- up to 4.3.4.1
- Fixed in:
- 4.3.4.2
- Disclosed:
- Jun 25, 2026
CVE-2026-56053 on NVD →
EventPrime – Events Calendar, Bookings and Tickets <= 4.3.2.1 - Unauthenticated PHP Object Injection
high
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.3.2.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable...
- CVSS:
- 8.1
- Affected:
- up to 4.3.2.1
- Fixed in:
- 4.3.2.2
- Disclosed:
- May 25, 2026
CVE-2026-42687 on NVD →
EventPrime – Events Calendar, Bookings and Tickets <= 4.3.2.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to in...
- CVSS:
- 6.4
- Affected:
- up to 4.3.2.1
- Fixed in:
- 4.3.2.2
- Disclosed:
- May 24, 2026
CVE-2026-42686 on NVD →
EventPrime – Events Calendar, Bookings and Tickets <= 4.3.2.0 - Missing Authorization
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.3.2.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.3.2.0
- Fixed in:
- 4.3.2.1
- Disclosed:
- May 12, 2026
CVE-2026-42669 on NVD →
EventPrime – Events Calendar, Bookings and Tickets <= 4.3.0.0 - Authenticated (Subscriber+) Insecure Direct Object Reference
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.0.0 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to p...
- CVSS:
- 4.3
- Affected:
- up to 4.3.0.0
- Fixed in:
- 4.3.0.1
- Disclosed:
- Apr 20, 2026
CVE-2026-39518 on NVD →
EventPrime – Events Calendar, Bookings and Tickets <= 4.2.8.3 - Missing Authorization
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.8.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.2.8.3
- Fixed in:
- 4.2.8.4
- Disclosed:
- Mar 18, 2026
CVE-2026-25312 on NVD →
EventPrime – Events Calendar, Bookings and Tickets <= 4.2.8.0 - Unauthenticated PHP Object Injection
high
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.8.0 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable...
- CVSS:
- 8.1
- Affected:
- up to 4.2.8.0
- Fixed in:
- 4.2.8.1
- Disclosed:
- Mar 17, 2026
CVE-2026-24378 on NVD →
EventPrime – Events Calendar, Bookings and Tickets <= 4.2.6.0 - Missing Authorization
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.6.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.2.6.0
- Fixed in:
- 4.2.7.0
- Disclosed:
- Mar 10, 2026
CVE-2025-69358 on NVD →
EventPrime <= 4.2.8.3 - Unauthenticated Information Exposure
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.8.3. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 4.2.8.3
- Fixed in:
- 4.2.8.4
- Disclosed:
- Feb 20, 2026
CVE-2026-25389 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] <= 4.2.8.3 (unfixed)
unknown
[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Retrieve Embedded Sensitive Data.This issue affects EventPrime: from n/a through <= 4.2.8.3.
- Affected:
- up to 4.2.8.3
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25389 on NVD →
EventPrime <= 4.2.8.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Event Modification via 'event_id' Parameter
medium
The EventPrime plugin for WordPress is vulnerable to unauthorized post modification due to missing authorization checks in all versions up to, and including, 4.2.8.4. This is due to the save_frontend_event_submission function accepting a user-controlled event_id parameter and updating the corresponding event post witho...
- CVSS:
- 4.3
- Affected:
- up to 4.2.8.4
- Fixed in:
- 4.2.8.5
- Disclosed:
- Feb 17, 2026
CVE-2026-1655 on NVD →
EventPrime <= 4.2.8.4 - Missing Authorization to Unauthenticated Image Upload via 'ep_upload_file_media' AJAX Endpoint
medium
The EventPrime plugin for WordPress is vulnerable to unauthorized image file upload in all versions up to, and including, 4.2.8.4. This is due to the plugin registering the upload_file_media AJAX action as publicly accessible (nopriv-enabled) without implementing any authentication, authorization, or nonce verification...
- CVSS:
- 5.3
- Affected:
- up to 4.2.8.4
- Fixed in:
- 4.2.8.5
- Disclosed:
- Feb 16, 2026
CVE-2026-1657 on NVD →
EventPrime <= 4.2.8.0 - Missing Authorization
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.8.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.2.8.0
- Fixed in:
- 4.2.8.1
- Disclosed:
- Jan 28, 2026
CVE-2026-24380 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] <= 4.2.8.0 (unfixed)
unknown
[en] Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <= 4.2.8.0.
- Affected:
- up to 4.2.8.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2026-24380 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 4.2.8.0
unknown
[en] The EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.7.0 via the REST API. This makes it possible for unauthenticated attackers to extract sensitive booking data including user names, email addresses, t...
- Affected:
- up to 4.2.8.0
- Fixed in:
- 4.2.8.0
- Disclosed:
- Jan 13, 2026
CVE-2025-14507 on NVD →
EventPrime - Events Calendar, Bookings and Tickets <= 4.2.7.0 - Unauthenticated Sensitive Information Exposure via REST API
medium
The EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.7.0 via the REST API. This makes it possible for unauthenticated attackers to extract sensitive booking data including user names, email addresses, ticket...
- CVSS:
- 5.3
- Affected:
- up to 4.2.7.0
- Fixed in:
- 4.2.8.0
- Disclosed:
- Jan 12, 2026
CVE-2025-14507 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] <= 4.2.4.1 (unfixed)
unknown
[en] Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <= 4.2.4.1.
- Affected:
- up to 4.2.4.1
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-63006 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] <= 4.2.4.1 (unfixed)
unknown
[en] Insertion of Sensitive Information Into Sent Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Retrieve Embedded Sensitive Data.This issue affects EventPrime: from n/a through <= 4.2.4.1.
- Affected:
- up to 4.2.4.1
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-63007 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 4.2.0.1
unknown
[en] The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized booking note creation due to a missing capability check on the 'booking_add_notes' function in all versions up to, and including, 4.2.0.0. This makes it possible for authenticated attackers, with Subscriber-le...
- Affected:
- up to 4.2.0.1
- Fixed in:
- 4.2.0.1
- Disclosed:
- Nov 8, 2025
CVE-2025-12498 on NVD →
EventPrime – Events Calendar, Bookings and Tickets <= 4.2.0.0 - Missing Authorization to Authenticated (Subscriber+) Booking Note Creation
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized booking note creation due to a missing capability check on the 'booking_add_notes' function in all versions up to, and including, 4.2.0.0. This makes it possible for authenticated attackers, with Subscriber-level a...
- CVSS:
- 4.3
- Affected:
- up to 4.2.0.0
- Fixed in:
- 4.2.0.1
- Disclosed:
- Nov 7, 2025
CVE-2025-12498 on NVD →
EventPrime <= 4.2.4.1 - Missing Authorization
medium
The EventPrime plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.2.4.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.2.4.1
- Fixed in:
- 4.2.5.0
- Disclosed:
- Nov 6, 2025
CVE-2025-63006 on NVD →
EventPrime <= 4.2.4.1 - Authenticated (Subscriber+) Information Exposure
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 4.2.4.1
- Fixed in:
- 4.2.5.0
- Disclosed:
- Nov 6, 2025
CVE-2025-63007 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 4.0.7.4
unknown
[en] The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the export_submittion_attendees function in all versions up to, and including, 4.0.7.3. This makes it possible for authenticated attackers, with Subscriber-...
- Affected:
- up to 4.0.7.4
- Fixed in:
- 4.0.7.4
- Disclosed:
- Mar 7, 2025
CVE-2024-13526 on NVD →
EventPrime – Events Calendar, Bookings and Tickets <= 4.0.7.3 - Missing Authorization to Authenticated (Subscriber+) Event Attendees Export
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the export_submittion_attendees function in all versions up to, and including, 4.0.7.3. This makes it possible for authenticated attackers, with Subscriber-level...
- CVSS:
- 4.3
- Affected:
- up to 4.0.7.3
- Fixed in:
- 4.0.7.4
- Disclosed:
- Mar 6, 2025
CVE-2024-13526 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 4.0.6.0
unknown
[en] The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the em_ticket_category_data and em_ticket_individual_data parameters in all versions up to, and including, 4.0.5.3 due to insufficient input sanitization and output escaping. This makes it p...
- Affected:
- up to 4.0.6.0
- Fixed in:
- 4.0.6.0
- Disclosed:
- Dec 17, 2024
CVE-2024-12024 on NVD →
EventPrime – Events Calendar, Bookings and Tickets <= 4.0.7.3 - Unauthenticated Stored Cross-Site Scripting via Ticket Category and Ticket Type Name
high
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the em_ticket_category_data and em_ticket_individual_data parameters in all versions up to, and including, 4.0.7.3 due to insufficient input sanitization and output escaping. This makes it possib...
- CVSS:
- 7.2
- Affected:
- up to 4.0.7.3
- Fixed in:
- 4.0.7.4
- Disclosed:
- Dec 16, 2024
CVE-2024-12024 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 4.0.4.0
unknown
[en] Missing Authorization vulnerability in EventPrime Events EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 4.0.3.2.
- Affected:
- up to 4.0.4.0
- Fixed in:
- 4.0.4.0
- Disclosed:
- Nov 1, 2024
CVE-2024-43223 on NVD →
EventPrime – Events Calendar, Bookings and Tickets <= 3.5.0 - Insecure Direct Object Reference to (Subscriber+) Arbitrary Booking Update
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.9 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upd...
- CVSS:
- 4.3
- Affected:
- up to 3.4.9
- Fixed in:
- 3.5.0
- Disclosed:
- Oct 29, 2024
CVE-2024-4665 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 4.0.4.8
unknown
[en] The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ep_booking_attendee_fields’ fields in all versions up to, and including, 4.0.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated a...
- Affected:
- up to 4.0.4.8
- Fixed in:
- 4.0.4.8
- Disclosed:
- Oct 24, 2024
CVE-2024-9865 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 4.0.4.8
unknown
[en] The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket names in all versions up to, and including, 4.0.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...
- Affected:
- up to 4.0.4.8
- Fixed in:
- 4.0.4.8
- Disclosed:
- Oct 24, 2024
CVE-2024-9864 on NVD →
EventPrime – Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket names in all versions up to, and including, 4.0.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...
- CVSS:
- 6.1
- Affected:
- up to 4.0.4.7
- Fixed in:
- 4.0.4.8
- Disclosed:
- Oct 23, 2024
CVE-2024-9864 on NVD →
EventPrime – Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting via Transaction Log
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ep_booking_attendee_fields’ fields in all versions up to, and including, 4.0.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attack...
- CVSS:
- 6.1
- Affected:
- up to 4.0.4.7
- Fixed in:
- 4.0.4.8
- Disclosed:
- Oct 23, 2024
CVE-2024-9865 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 4.0.4.6
unknown
[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in EventPrime Events EventPrime.This issue affects EventPrime: from n/a through 4.0.4.5.
- Affected:
- up to 4.0.4.6
- Fixed in:
- 4.0.4.6
- Disclosed:
- Oct 10, 2024
CVE-2024-47648 on NVD →
EventPrime <= 4.0.4.5 - Open Redirect
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 4.0.4.5. This is due to insufficient validation on a redirect url supplied. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sit...
- CVSS:
- 6.1
- Affected:
- up to 4.0.4.5
- Fixed in:
- 4.0.4.6
- Disclosed:
- Sep 30, 2024
CVE-2024-47648 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 4.0.4.4
unknown
[en] The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected events due to missing authorization checks in all versions up to, and including, 4.0.4.3. This makes it possible for unauthenticated attackers to view private or passwor...
- Affected:
- up to 4.0.4.4
- Fixed in:
- 4.0.4.4
- Disclosed:
- Sep 10, 2024
CVE-2024-8369 on NVD →
EventPrime <= 4.0.4.3 - Missing Authorization to Unauthenticated Private or Password-Protected Events Disclosure
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected events due to missing authorization checks in all versions up to, and including, 4.0.4.3. This makes it possible for unauthenticated attackers to view private or password-pro...
- CVSS:
- 5.3
- Affected:
- up to 4.0.4.3
- Fixed in:
- 4.0.4.4
- Disclosed:
- Sep 9, 2024
CVE-2024-8369 on NVD →
EventPrime <= 4.0.3.2 - Missing Authorization via calendar_event_create()
medium
The EventPrime plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the calendar_event_create() function in versions up to, and including, 4.0.3.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to create calendar event...
- CVSS:
- 5.3
- Affected:
- up to 4.0.3.2
- Fixed in:
- 4.0.4.0
- Disclosed:
- Aug 9, 2024
CVE-2024-43223 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.3.5
unknown
[en] Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.4.
- Affected:
- up to 3.3.5
- Fixed in:
- 3.3.5
- Disclosed:
- Jun 9, 2024
CVE-2024-31275 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.0.0
unknown
[en] Missing Authorization vulnerability in Metagauss EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 2.8.6.
- Affected:
- up to 3.0.0
- Fixed in:
- 3.0.0
- Disclosed:
- May 17, 2024
CVE-2023-33321 on NVD →
EventPrime <= 3.3.4 - Missing Authorization to Booking Price Maniputlation
medium
The EventPrime plugin for WordPress is vulnerable to booking price manipulations due to insufficient validation and control of booking prices in versions up to, and including, 3.3.4. This makes it possible for unauthenticated attackers to make bookings with lower prices.
- CVSS:
- 5.3
- Affected:
- up to 3.3.4
- Fixed in:
- 3.3.5
- Disclosed:
- Apr 5, 2024
CVE-2024-31275 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.4.0
unknown
[en] Cross Site Scripting (XSS) vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.
- Affected:
- up to 3.4.0
- Fixed in:
- 3.4.0
- Disclosed:
- Mar 27, 2024
CVE-2024-29776 on NVD →
EventPrime <= 3.3.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The EventPrime plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitr...
- CVSS:
- 5.5
- Affected:
- up to 3.3.9
- Fixed in:
- 3.4.0
- Disclosed:
- Mar 25, 2024
CVE-2024-29776 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.4.0
unknown
[en] Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.
- Affected:
- up to 3.4.0
- Fixed in:
- 3.4.0
- Disclosed:
- Mar 23, 2024
CVE-2024-24832 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.4.3
unknown
[en] The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 3.4.2. This is due to the plugin allowing unauthenticated users to update the status of order payments. This makes it possible for unauthenticated attackers to book even...
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.3
- Disclosed:
- Mar 13, 2024
CVE-2024-1321 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.4.3
unknown
[en] The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_attendees_email_by_event_id() function in all versions up to, and including, 3.4.1. This makes it possible for authenticated attackers, with subscrib...
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.3
- Disclosed:
- Mar 13, 2024
CVE-2024-1126 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.4.2
unknown
[en] The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the booking_export_all() function in all versions up to, and including, 3.4.1. This makes it possible for authenticated attackers, with subscriber-level acce...
- Affected:
- up to 3.4.2
- Fixed in:
- 3.4.2
- Disclosed:
- Mar 13, 2024
CVE-2024-1127 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.4.4
unknown
[en] The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the ep_send_attendees_email() function in all versions up to, and including, 3.4.1. This makes it possible for authenticated attackers, with subscriber-level...
- Affected:
- up to 3.4.4
- Fixed in:
- 3.4.4
- Disclosed:
- Mar 9, 2024
CVE-2024-1124 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.4.4
unknown
[en] The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'offline_status' parameter in all versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...
- Affected:
- up to 3.4.4
- Fixed in:
- 3.4.4
- Disclosed:
- Mar 9, 2024
CVE-2024-1320 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.4.3
unknown
[en] The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_frontend_event_submission() function in all versions up to, and including, 3.4.2. This makes it possible for authenticated attackers, with sub...
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.3
- Disclosed:
- Mar 9, 2024
CVE-2024-1123 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.4.4
unknown
[en] The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the calendar_events_delete() function in all versions up to, and including, 3.4.3. This makes it possible for authenticated attackers, with subscriber-level ac...
- Affected:
- up to 3.4.4
- Fixed in:
- 3.4.4
- Disclosed:
- Mar 9, 2024
CVE-2024-1125 on NVD →
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.3 - Unauthenticated Stored Cross-Site Scripting
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'offline_status' parameter in all versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje...
- CVSS:
- 6.5
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.4
- Disclosed:
- Mar 8, 2024
CVE-2024-1320 on NVD →
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Missing Authorization to Arbitrary Post Overwrite
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_frontend_event_submission() function in all versions up to, and including, 3.4.2. This makes it possible for authenticated attackers, with subscrib...
- CVSS:
- 6.5
- Affected:
- up to 3.4.2
- Fixed in:
- 3.4.3
- Disclosed:
- Mar 8, 2024
CVE-2024-1123 on NVD →
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the calendar_events_delete() function in all versions up to, and including, 3.4.3. This makes it possible for authenticated attackers, with subscriber-level access...
- CVSS:
- 5.4
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.4
- Disclosed:
- Mar 8, 2024
CVE-2024-1125 on NVD →
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Unauthenticated Booking Payment Bypass
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 3.4.2. This is due to the plugin allowing unauthenticated users to update the status of order payments. This makes it possible for unauthenticated attackers to book events fo...
- CVSS:
- 5.3
- Affected:
- up to 3.4.2
- Fixed in:
- 3.4.3
- Disclosed:
- Mar 8, 2024
CVE-2024-1321 on NVD →
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the ep_send_attendees_email() function in all versions up to, and including, 3.4.1. This makes it possible for authenticated attackers, with subscriber-level acces...
- CVSS:
- 4.3
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.4
- Disclosed:
- Mar 8, 2024
CVE-2024-1124 on NVD →
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Missing Authorization to Authenticated (Subscriber+) Attendee List Retrieval
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_attendees_email_by_event_id() function in all versions up to, and including, 3.4.2. This makes it possible for authenticated attackers, with subscriber-le...
- CVSS:
- 4.3
- Affected:
- up to 3.4.2
- Fixed in:
- 3.4.3
- Disclosed:
- Feb 14, 2024
CVE-2024-1126 on NVD →
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Event Export
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the booking_export_all() function in all versions up to, and including, 3.4.1. This makes it possible for authenticated attackers, with subscriber-level access an...
- CVSS:
- 4.3
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.2
- Disclosed:
- Feb 14, 2024
CVE-2024-1127 on NVD →
EventPrime <= 3.3.9 - Improper Input Validation via save_event_booking
medium
The EventPrime plugin for WordPress is vulnerable to unauthorized modification of data due to improper input validation in the 'save_event_booking' function in versions up to, and including, 3.3.9. This makes it possible for unauthenticated attackers to modify the price and other attributes of purchased tickets.
- CVSS:
- 5.3
- Affected:
- up to 3.3.9
- Fixed in:
- 3.4.0
- Disclosed:
- Feb 2, 2024
CVE-2024-24832 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.3.6
unknown
[en] The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id/event name.
- Affected:
- up to 3.3.6
- Fixed in:
- 3.3.6
- Disclosed:
- Jan 22, 2024
CVE-2023-6447 on NVD →
EventPrime <= 3.3.5 - Missing Authorization to Private Event Disclosure
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in all versions up to, and including, 3.3.5. This makes it possible for unauthenticated attackers to retrieve password protected and private events.
- CVSS:
- 5.3
- Affected:
- up to 3.3.5
- Fixed in:
- 3.3.6
- Disclosed:
- Dec 29, 2023
CVE-2023-6447 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.3.3
unknown
[en] The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attacker to purchase bookings without payment.
- Affected:
- up to 3.3.3
- Fixed in:
- 3.3.3
- Disclosed:
- Nov 27, 2023
CVE-2023-4252 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.3.3
unknown
Update the WordPress EventPrime plugin to the latest available version (at least 3.3.3).
Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress EventPrime Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payload...
- Affected:
- up to 3.3.3
- Fixed in:
- 3.3.3
- Disclosed:
- Nov 23, 2023
EventPrime – Modern Events Calendar, Bookings and Tickets <= 3.3.2 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica...
- CVSS:
- 6.4
- Affected:
- up to 3.3.2
- Fixed in:
- 3.3.3
- Disclosed:
- Nov 21, 2023
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.3.3
unknown
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica...
- Affected:
- up to 3.3.3
- Fixed in:
- 3.3.3
- Disclosed:
- Nov 21, 2023
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.2.0
unknown
[en] The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
- Affected:
- up to 3.2.0
- Fixed in:
- 3.2.0
- Disclosed:
- Oct 31, 2023
CVE-2023-4250 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.2.0
unknown
[en] The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks.
- Affected:
- up to 3.2.0
- Fixed in:
- 3.2.0
- Disclosed:
- Oct 31, 2023
CVE-2023-4251 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.2.0
unknown
[en] The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks.
- Affected:
- up to 3.2.0
- Fixed in:
- 3.2.0
- Disclosed:
- Oct 31, 2023
CVE-2023-5519 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.2.0
unknown
[en] The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to an HTML Injection on the plugin in the search area of the website.
- Affected:
- up to 3.2.0
- Fixed in:
- 3.2.0
- Disclosed:
- Oct 31, 2023
CVE-2023-5238 on NVD →
EventPrime <= 3.3.2 - Improper Server-Side Checks to Booking Payment Bypass
medium
The EventPrime plugin for WordPress is vulnerable to booking payment bypass in all versions up to, and including, 3.3.2. This is due to the plugin relying on user supplied input to control pricing instead of server-side controls/validation. This makes it possible for unauthenticated attackers to make bookings paying le...
- CVSS:
- 5.3
- Affected:
- up to 3.3.2
- Fixed in:
- 3.3.3
- Disclosed:
- Oct 30, 2023
CVE-2023-4252 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.1.6
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime EventPrime – Events Calendar, Bookings and Tickets plugin <= 3.1.5 versions.
- Affected:
- up to 3.1.6
- Fixed in:
- 3.1.6
- Disclosed:
- Oct 24, 2023
CVE-2023-45637 on NVD →
EventPrime <= 3.1.5 - Reflected Cross-Site Scripting via 'event_id'
medium
The EventPrime plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘event_id’ parameter in versions up to, and including, 3.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 3.1.5
- Fixed in:
- 3.1.6
- Disclosed:
- Oct 11, 2023
CVE-2023-45637 on NVD →
EventPrime < 3.2.0 - Reflected Cross-Site Scripting via keyword and ep_filter_date
medium
The EventPrime plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the keyword and ep_filter_date parameters in versions up to 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 3.2.0
- Fixed in:
- 3.2.0
- Disclosed:
- Oct 9, 2023
CVE-2023-4250 on NVD →
EventPrime < 3.2.0 - Reflected HTML Content Injection
medium
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Reflected HTML Content Injection via the search parameter in all versions up to 3.2.0 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitr...
- CVSS:
- 4.3
- Affected:
- up to 3.2.0
- Fixed in:
- 3.2.0
- Disclosed:
- Oct 9, 2023
CVE-2023-5238 on NVD →
EventPrime < 3.2.0 - Cross-Site Request Forgery
medium
The EventPrime plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 3.2.0. This is due to missing or incorrect nonce validation one of its functions. This makes it possible for unauthenticated attackers to create event bookings via a forged request granted they can trick a site administrat...
- CVSS:
- 4.3
- Affected:
- up to 3.2.0
- Fixed in:
- 3.2.0
- Disclosed:
- Oct 9, 2023
CVE-2023-4251 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.0.6
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 3.0.5 versions.
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.6
- Disclosed:
- Jun 20, 2023
CVE-2023-35884 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.0.0
unknown
[en] Unauth. Reflected (XSS) Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 2.8.6 versions.
- Affected:
- up to 3.0.0
- Fixed in:
- 3.0.0
- Disclosed:
- May 28, 2023
CVE-2023-33326 on NVD →
EventPrime <= 3.0.5 - Reflected Cross-Site Scripting
medium
The EventPrime plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tric...
- CVSS:
- 6.1
- Affected:
- up to 3.0.5
- Fixed in:
- 3.0.6
- Disclosed:
- May 22, 2023
CVE-2023-35884 on NVD →
EventPrime <= 2.8.6 - Reflected Cross-Site Scripting
medium
The EventPrime plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.8.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tric...
- CVSS:
- 6.1
- Affected:
- up to 2.8.6
- Fixed in:
- 3.0.0
- Disclosed:
- May 22, 2023
CVE-2023-33326 on NVD →
EventPrime <= 2.8.6 - Sensitive Information Exposure
medium
The EventPrime plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.8.6. This could allow unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 2.8.6
- Fixed in:
- 3.0.0
- Disclosed:
- May 22, 2023
CVE-2023-33321 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.5.0
unknown
- Affected:
- up to 3.5.0
- Fixed in:
- 3.5.0
CVE-2024-4665 on NVD →
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.4.0
unknown
Update the WordPress EventPrime plugin to the latest available version (at least 3.4.0).
Abdi Pranata discovered and reported this Broken Access Control vulnerability in WordPress EventPrime Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that c...
- Affected:
- up to 3.4.0
- Fixed in:
- 3.4.0
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] < 3.3.3
unknown
The plugin does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin
- Affected:
- up to 3.3.3
- Fixed in:
- 3.3.3