Events Manager <= 7.4.0.1 - Reflected Cross-Site Scripting via 'header_format' Parameter
medium
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'header_format' parameter in all versions up to, and including, 7.4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacker...
- CVSS:
- 6.1
- Affected:
- up to 7.4.0.1
- Fixed in:
- 7.4.1
- Disclosed:
- Aug 24, 2026
CVE-2026-17089 on NVD →
Events Manager <= 7.3.7.4 - Authenticated (Administrator+) Local File Inclusion via 'dbem_data[updates]' Array Keys
medium
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.3.7.4 via the em_options_save function. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arb...
- CVSS:
- 6.6
- Affected:
- up to 7.3.7.4
- Fixed in:
- 7.4
- Disclosed:
- Aug 24, 2026
CVE-2026-14280 on NVD →
Events Manager <= 7.4.0 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'status', 'private', and 'private_only' Parameters
medium
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to vie...
- CVSS:
- 5.3
- Affected:
- up to 7.4.0
- Fixed in:
- 7.4.1
- Disclosed:
- Aug 24, 2026
CVE-2026-10627 on NVD →
Events Manager <= 7.4.0 - Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter in Event/Location Duplicate Action
medium
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to generic SQL Injection via Stored 'meta_key' via Event/Location Duplicate Action in all versions up to, and including, 7.4.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on...
- CVSS:
- 6.5
- Affected:
- up to 7.4.0
- Fixed in:
- 7.4.1
- Disclosed:
- Aug 24, 2026
CVE-2026-15023 on NVD →
Events Manager <= 7.4.0 - Unauthenticated Privilege Escalation
high
The Events Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 7.4.0. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for unauthenticated attackers to elevate their privileges beyond those intended for their...
- CVSS:
- 7.3
- Affected:
- up to 7.4.0
- Fixed in:
- 7.4.1
- Disclosed:
- Aug 10, 2026
CVE-2026-18366 on NVD →
Events Manager <= 7.4.0 - Authenticated (Subscriber+) SQL Injection
medium
The Events Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.4.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and ab...
- CVSS:
- 6.5
- Affected:
- up to 7.4.0
- Fixed in:
- 7.4.1
- Disclosed:
- Aug 10, 2026
CVE-2026-18057 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! <= 7.4.2 - Unauthenticated Stored Cross-Site Scripting
high
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 7.2
- Affected:
- up to 7.4.2
- Fix:
- No patched version reported
- Disclosed:
- Aug 4, 2026
CVE-2026-66457 on NVD →
Events Manager <= 7.3 - Unauthenticated Pending Upload Disclosure
medium
The Events Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.3. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 7.3
- Fixed in:
- 7.4
- Disclosed:
- Jul 30, 2026
CVE-2026-18050 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! <= 7.3.6 - Unauthenticated PHP Object Injection
high
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 7.3.6 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnera...
- CVSS:
- 8.1
- Affected:
- up to 7.3.6
- Fixed in:
- 7.3.7
- Disclosed:
- Jul 8, 2026
CVE-2026-57713 on NVD →
Events Manager <= 7.3.6 - Unauthenticated SQL Injection
high
The Events Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries i...
- CVSS:
- 7.5
- Affected:
- up to 7.3.6
- Fixed in:
- 7.3.7
- Disclosed:
- Jul 1, 2026
CVE-2026-12987 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.2.3
unknown
[en] The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list_grouped' shortcode in all versions up to, and including, 7.2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This m...
- Affected:
- up to 7.2.3
- Fixed in:
- 7.2.3
- Disclosed:
- Dec 18, 2025
CVE-2025-12976 on NVD →
Events Manager <= 7.2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'events_list_grouped' Shortcode
medium
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list_grouped' shortcode in all versions up to, and including, 7.2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes...
- CVSS:
- 6.4
- Affected:
- up to 7.2.2.1
- Fixed in:
- 7.2.3
- Disclosed:
- Dec 17, 2025
CVE-2025-12976 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.2.2.3
unknown
[en] The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 7.2.2.2 via the 'get_location' action due to insufficient restrictions on which locations can be included. This makes it possible for unauthenticated attacker...
- Affected:
- up to 7.2.2.3
- Fixed in:
- 7.2.2.3
- Disclosed:
- Dec 12, 2025
CVE-2025-12408 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.2.2.3
unknown
[en] The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.2.2. This is due to missing or incorrect nonce validation on the 'location_delete' action. This makes it possible for unauthenticated attackers to d...
- Affected:
- up to 7.2.2.3
- Fixed in:
- 7.2.2.3
- Disclosed:
- Dec 12, 2025
CVE-2025-12407 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! <= 7.2.2.2 - Cross-Site Request Forgery to Location Deletion
medium
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.2.2. This is due to missing or incorrect nonce validation on the 'location_delete' action. This makes it possible for unauthenticated attackers to delete...
- CVSS:
- 4.3
- Affected:
- up to 7.2.2.2
- Fixed in:
- 7.2.2.3
- Disclosed:
- Dec 11, 2025
CVE-2025-12407 on NVD →
Events Manager <= 7.2.2.2 - Unauthenticated Information Exposure
medium
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 7.2.2.2 via the 'get_location' action due to insufficient restrictions on which locations can be included. This makes it possible for unauthenticated attackers to...
- CVSS:
- 5.3
- Affected:
- up to 7.2.2.2
- Fixed in:
- 7.2.2.3
- Disclosed:
- Dec 11, 2025
CVE-2025-12408 on NVD →
Events Manager <= 7.0.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes
medium
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authen...
- CVSS:
- 6.4
- Affected:
- up to 6.6.4.4, 7.0.1 – 7.0.3
- Fixed in:
- 6.6.5
- Disclosed:
- Jul 9, 2025
CVE-2025-6976 on NVD →
Events Manager <= 7.0.3 - Unauthenticated SQL Injection via `orderby` Parameter
high
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Th...
- CVSS:
- 7.5
- Affected:
- up to 6.6.4.4, 7.0.1 – 7.0.3
- Fixed in:
- 6.6.5
- Disclosed:
- Jul 9, 2025
CVE-2025-6970 on NVD →
Event Manager <= 7.0.3 - Reflected Cross-Site Scripting via `calendar_header` Parameter
medium
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘calendar_header’ parameter in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacker...
- CVSS:
- 6.1
- Affected:
- up to 6.6.4.4, 7.0.1 – 7.0.3
- Fixed in:
- 6.6.5
- Disclosed:
- Jul 9, 2025
CVE-2025-6975 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! <= 6.6.4.1 - Missing Authorization
medium
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.6.4.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 6.6.4.1
- Fixed in:
- 6.6.4.2
- Disclosed:
- Feb 26, 2025
CVE-2025-1249 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.6.4
unknown
[en] The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL q...
- Affected:
- up to 6.6.4
- Fixed in:
- 6.6.4
- Disclosed:
- Feb 21, 2025
CVE-2024-11260 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! <= 6.6.3 - Unauthenticated SQL Injection via Event Status Parameter
high
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query....
- CVSS:
- 7.5
- Affected:
- up to 6.6.3
- Fixed in:
- 6.6.4
- Disclosed:
- Feb 20, 2025
CVE-2024-11260 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.9
unknown
[en] The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers t...
- Affected:
- up to 6.4.9
- Fixed in:
- 6.4.9
- Disclosed:
- Jun 29, 2024
CVE-2024-5889 on NVD →
Events Manager <= 6.4.8 - Reflected Cross-Site Scripting
medium
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inj...
- CVSS:
- 6.1
- Affected:
- up to 6.4.8
- Fixed in:
- 6.4.9
- Disclosed:
- Jun 28, 2024
CVE-2024-5889 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.8
unknown
[en] The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' shortcodes in all versions up to, and including, 6.4.7.3 due to insufficient input sanitization and output escaping on user suppli...
- Affected:
- up to 6.4.8
- Fixed in:
- 6.4.8
- Disclosed:
- Jun 12, 2024
CVE-2024-3492 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! <= 6.4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via event, location, and event_category Shortcodes
medium
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' shortcodes in all versions up to, and including, 6.4.7.3 due to insufficient input sanitization and output escaping on user supplied at...
- CVSS:
- 6.4
- Affected:
- up to 6.4.7.3
- Fixed in:
- 6.4.8
- Disclosed:
- Jun 11, 2024
CVE-2024-3492 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.7
unknown
[en] Missing Authorization vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.6.4.
- Affected:
- up to 6.4.7
- Fixed in:
- 6.4.7
- Disclosed:
- Jun 9, 2024
CVE-2024-30515 on NVD →
Events Manager <= 6.4.7.1 - Cross-Site Request Forgery
medium
The Events Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.7.1. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site a...
- CVSS:
- 4.3
- Affected:
- up to 6.4.7.1
- Fixed in:
- 6.4.7.2
- Disclosed:
- Mar 28, 2024
CVE-2024-30421 on NVD →
Events Manager <= 6.4.6.4 - Missing Authorization
medium
The Events Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 6.4.6.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.
- CVSS:
- 4.3
- Affected:
- up to 6.4.6.4
- Fixed in:
- 6.4.7
- Disclosed:
- Mar 28, 2024
CVE-2024-30515 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.7.2
unknown
[en] The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.7.1. This is due to missing or incorrect nonce validation on several actions. This makes it possible for unauthenticated attackers to modify booking...
- Affected:
- up to 6.4.7.2
- Fixed in:
- 6.4.7.2
- Disclosed:
- Mar 28, 2024
CVE-2024-2110 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.7.2
unknown
[en] The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the physical location value in all versions up to, and including, 6.4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...
- Affected:
- up to 6.4.7.2
- Fixed in:
- 6.4.7.2
- Disclosed:
- Mar 28, 2024
CVE-2024-2111 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.7.2
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.7.1.
- Affected:
- up to 6.4.7.2
- Fixed in:
- 6.4.7.2
- Disclosed:
- Mar 28, 2024
CVE-2024-30421 on NVD →
Events Manager <= 6.4.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the physical location value in all versions up to, and including, 6.4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with...
- CVSS:
- 6.4
- Affected:
- up to 6.4.7.1
- Fixed in:
- 6.4.7.2
- Disclosed:
- Mar 27, 2024
CVE-2024-2111 on NVD →
Events Manager <= 6.4.7.1 - Cross-Site Request Forgery
medium
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.7.1. This is due to missing or incorrect nonce validation on several actions. This makes it possible for unauthenticated attackers to modify booking stat...
- CVSS:
- 4.3
- Affected:
- up to 6.4.7.1
- Fixed in:
- 6.4.7.2
- Disclosed:
- Mar 27, 2024
CVE-2024-2110 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.7
unknown
[en] The Events Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.4.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to in...
- Affected:
- up to 6.4.7
- Fixed in:
- 6.4.7
- Disclosed:
- Mar 13, 2024
CVE-2024-0614 on NVD →
Events Manager <= 6.4.6.4 - Authenticated(Administator+) Stored Cross-Site Scripting via settings
medium
The Events Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.4.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...
- CVSS:
- 4.4
- Affected:
- up to 6.4.6.4
- Fixed in:
- 6.4.7
- Disclosed:
- Feb 28, 2024
CVE-2024-0614 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.6
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager allows Reflected XSS.This issue affects Events Manager: from n/a through 6.4.5.
- Affected:
- up to 6.4.6
- Fixed in:
- 6.4.6
- Disclosed:
- Nov 30, 2023
CVE-2023-48326 on NVD →
Events Manager <= 6.4.5 - Reflected Cross-Site Scripting
medium
The Events Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions up to, and including, 6.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...
- CVSS:
- 6.1
- Affected:
- up to 6.4.5
- Fixed in:
- 6.4.6
- Disclosed:
- Nov 23, 2023
CVE-2023-48326 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.8
unknown
[en] The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues
- Affected:
- up to 5.9.8
- Fixed in:
- 5.9.8
- Disclosed:
- Dec 1, 2021
CVE-2020-35037 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.8
unknown
[en] The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection
- Affected:
- up to 5.9.8
- Fixed in:
- 5.9.8
- Disclosed:
- Dec 1, 2021
CVE-2020-35012 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.8
unknown
SQL Injection (SQLi) vulnerability found by Antony Garand in WordPress Events Manager plugin (versions <= 5.9.7.3).
- Affected:
- up to 5.9.8
- Fixed in:
- 5.9.8
- Disclosed:
- Nov 30, 2020
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.8
unknown
Cross-Site Scripting (XSS) vulnerability found by Jakob Wierzba in WordPress Events Manager plugin (versions <= 5.9.7.3).
- Affected:
- up to 5.9.8
- Fixed in:
- 5.9.8
- Disclosed:
- Nov 30, 2020
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.8.2
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Nguyen Van Khanh in WordPress Events Manager plugin (versions <= 5.9.8.1).
- Affected:
- up to 5.9.8.2
- Fixed in:
- 5.9.8.2
- Disclosed:
- Nov 25, 2020
Events Manager <= 5.9.7.3 - Admin+ SQL Injection
high
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection
- CVSS:
- 7.2
- Affected:
- up to 5.9.7.3
- Fixed in:
- 5.9.8
- Disclosed:
- Jun 7, 2020
CVE-2020-35012 on NVD →
Events Manager <= 5.9.7.3 - Cross-Site Scripting
medium
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues
- CVSS:
- 6.1
- Affected:
- up to 5.9.7.3
- Fixed in:
- 5.9.8
- Disclosed:
- Jun 7, 2020
CVE-2020-35037 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.7.2
unknown
CSV Injection vulnerability found by Vishnupriya Ilango in WordPress Events Manager plugin (versions <= 5.9.7.1).
- Affected:
- up to 5.9.7.2
- Fixed in:
- 5.9.7.2
- Disclosed:
- Feb 7, 2020
Events Manager < 5.9.7.2 & Events Manager Pro < 2.6.7.2 - Unauthenticated CSV Injection
high
The Events Manager Pro, versions up to 2.6.7.2, and Events Manager, versions up to 5.9.7.2, plugins for WordPress are vulnerable to CSV Injection. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a lo...
- CVSS:
- 7.1
- Affected:
- up to 5.9.7.2
- Fixed in:
- 5.9.7.2
- Disclosed:
- Feb 6, 2020
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.7.2
unknown
The Events Manager Pro, versions up to 2.6.7.2, and Events Manager, versions up to 5.9.7.2, plugins for WordPress are vulnerable to CSV Injection. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a lo...
- Affected:
- up to 5.9.7.2
- Fixed in:
- 5.9.7.2
- Disclosed:
- Feb 6, 2020
Events Manager <= 5.9.7.1 - CSV Injection
medium
The Events Manager plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 5.9.7.1 through the use of the Microsoft Excel DDE function. This allows low-privileged attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded...
- CVSS:
- 5.5
- Affected:
- up to 5.9.7.1
- Fixed in:
- 5.9.7.2
- Disclosed:
- Feb 5, 2020
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.7.2
unknown
The Events Manager plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 5.9.7.1 through the use of the Microsoft Excel DDE function. This allows low-privileged attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded...
- Affected:
- up to 5.9.7.2
- Fixed in:
- 5.9.7.2
- Disclosed:
- Feb 5, 2020
Events Manager <= 5.9.5 - Authenticated Stored Cross-Site Scripting
medium
The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and events_map) provided by the plugin.
- CVSS:
- 6.4
- Affected:
- up to 5.9.5
- Fixed in:
- 5.9.6
- Disclosed:
- Oct 16, 2019
CVE-2019-16523 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.6
unknown
[en] The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and events_map) provided by the plugin.
- Affected:
- up to 5.9.6
- Fixed in:
- 5.9.6
- Disclosed:
- Oct 16, 2019
CVE-2019-16523 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.5.2
unknown
[en] The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.
- Affected:
- up to 5.5.2
- Fixed in:
- 5.5.2
- Disclosed:
- Aug 22, 2019
CVE-2013-7477 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.1.7
unknown
[en] The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links.
- Affected:
- up to 5.1.7
- Fixed in:
- 5.1.7
- Disclosed:
- Aug 22, 2019
CVE-2012-6716 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.5
unknown
[en] The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.
- Affected:
- up to 5.5
- Fixed in:
- 5.5
- Disclosed:
- Aug 22, 2019
CVE-2013-7478 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.3.6.1
unknown
[en] The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.
- Affected:
- up to 5.3.6.1
- Fixed in:
- 5.3.6.1
- Disclosed:
- Aug 22, 2019
CVE-2013-7480 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.3.9
unknown
[en] The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.
- Affected:
- up to 5.3.9
- Fixed in:
- 5.3.9
- Disclosed:
- Aug 22, 2019
CVE-2013-7479 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.6
unknown
[en] The events-manager plugin before 5.6 for WordPress has XSS.
- Affected:
- up to 5.6
- Fixed in:
- 5.6
- Disclosed:
- Aug 13, 2019
CVE-2015-9297 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.5.7.1
unknown
[en] The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS.
- Affected:
- up to 5.5.7.1
- Fixed in:
- 5.5.7.1
- Disclosed:
- Aug 13, 2019
CVE-2015-9299 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.6
unknown
[en] The events-manager plugin before 5.6 for WordPress has code injection.
- Affected:
- up to 5.6
- Fixed in:
- 5.6
- Disclosed:
- Aug 13, 2019
CVE-2015-9298 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.5.7
unknown
[en] The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues.
- Affected:
- up to 5.5.7
- Fixed in:
- 5.5.7
- Disclosed:
- Aug 13, 2019
CVE-2015-9300 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.5
unknown
[en] The Events Manager plugin 5.9.4 for WordPress has XSS via the dbem_event_reapproved_email_body parameter to the wp-admin/edit.php?post_type=event&page=events-manager-options URI.
- Affected:
- up to 5.9.5
- Fixed in:
- 5.9.5
- Disclosed:
- Apr 12, 2019
CVE-2018-13137 on NVD →
Events Manager <= 5.9.4 - Cross-Site Scripting
medium
The Events Manager plugin 5.9.4 for WordPress has XSS via the dbem_event_reapproved_email_body parameter to the wp-admin/edit.php?post_type=event&page=events-manager-options URI.
- CVSS:
- 4.8
- Affected:
- up to 5.9.4
- Fixed in:
- 5.9.5
- Disclosed:
- Jul 18, 2018
CVE-2018-13137 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9
unknown
[en] Cross-site scripting vulnerability in Events Manager plugin prior to version 5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- Affected:
- up to 5.9
- Fixed in:
- 5.9
- Disclosed:
- May 14, 2018
CVE-2018-0576 on NVD →
Events Manager <= 5.8.1.3 - Stored Cross-Site Scripting
medium
Cross-site scripting vulnerability in Events Manager plugin prior to version 5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS:
- 5.4
- Affected:
- up to 5.9
- Fixed in:
- 5.9
- Disclosed:
- Apr 27, 2018
CVE-2018-0576 on NVD →
Events Manager <= 5.8.1.1 - Cross-Site Scripting
medium
The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature.
- CVSS:
- 6.4
- Affected:
- up to 5.8.1.2
- Fixed in:
- 5.8.1.2
- Disclosed:
- Mar 26, 2018
CVE-2018-9020 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.8.1.2
unknown
[en] The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature.
- Affected:
- up to 5.8.1.2
- Fixed in:
- 5.8.1.2
- Disclosed:
- Mar 26, 2018
CVE-2018-9020 on NVD →
Events Manager <= 5.5.7.1 - Code Injection
critical
The Events Manager plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 5.5.7.1. This makes it possible for attackers to inject code onto the server and potentially execute it.
- CVSS:
- 9.8
- Affected:
- up to 5.6
- Fixed in:
- 5.6
- Disclosed:
- Aug 10, 2015
CVE-2015-9298 on NVD →
Events Manager <= 5.5.7.1 - Cross-Site Scripting
medium
The events-manager plugin before 5.6 for WordPress has XSS.
- CVSS:
- 6.1
- Affected:
- up to 5.6
- Fixed in:
- 5.6
- Disclosed:
- Aug 10, 2015
CVE-2015-9297 on NVD →
Events Manager < 5.5.7.1 - Cross-Site Scripting
medium
The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS via the dbem_event_reapproved_email_body parameter.
- CVSS:
- 6.1
- Affected:
- up to 5.5.7.1
- Fixed in:
- 5.5.7.1
- Disclosed:
- Jun 4, 2015
CVE-2015-9299 on NVD →
Events Manager < 5.5.7 - Cross-Site Scripting
medium
The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues.
- CVSS:
- 6.1
- Affected:
- up to 5.5.7
- Fixed in:
- 5.5.7
- Disclosed:
- May 23, 2015
CVE-2015-9300 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.5.2
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 5.5.2
- Fixed in:
- 5.5.2
- Disclosed:
- May 15, 2015
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.3.9
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 5.3.9
- Fixed in:
- 5.3.9
- Disclosed:
- May 15, 2015
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.3.6
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 5.3.6
- Fixed in:
- 5.3.6
- Disclosed:
- May 15, 2015
Events Manager <= 5.5.1 - Multiple Cross-Site Scripting
medium
The Events Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 5.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 5.5.1
- Fixed in:
- 5.5.2
- Disclosed:
- Aug 1, 2014
CVE-2013-7477 on NVD →
Events Manager < 5.3.5 & Events Manager Pro < 2.2.9 - Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) scope parameter to index.php; (2) user_name, (3) dbem_phone, (4) user_email, or (5) booking_com...
- CVSS:
- 6.1
- Affected:
- up to 5.3.5
- Fixed in:
- 5.3.5
- Disclosed:
- Aug 1, 2014
CVE-2013-1407 on NVD →
Events Manager < 5.3.9 - Cross-Site Scripting
medium
The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.
- CVSS:
- 6.1
- Affected:
- up to 5.3.9
- Fixed in:
- 5.3.9
- Disclosed:
- Aug 1, 2014
CVE-2013-7479 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.3.5
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) scope parameter to index.php; (2) user_name, (3) dbem_phone, (4) user_email, or (5) bookin...
- Affected:
- up to 5.3.5
- Fixed in:
- 5.3.5
- Disclosed:
- May 13, 2014
CVE-2013-1407 on NVD →
Events Manager < 5.5 - Cross-Site Scripting
medium
The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.
- CVSS:
- 6.1
- Affected:
- up to 5.5
- Fixed in:
- 5.5
- Disclosed:
- Aug 14, 2013
CVE-2013-7478 on NVD →
Events Manager <= 5.3.6 - Multiple Cross-Site Scripting
medium
The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.
- CVSS:
- 6.1
- Affected:
- up to 5.3.6
- Fixed in:
- 5.3.6.1
- Disclosed:
- Feb 27, 2013
CVE-2013-7480 on NVD →
Events Manager < 5.1.7 - Cross-Site Scripting
medium
The Events Manager plugin before 5.1.7 for WordPress has XSS via JSON call links.
- CVSS:
- 6.1
- Affected:
- up to 5.1.7
- Fixed in:
- 5.1.7
- Disclosed:
- May 22, 2012
CVE-2012-6716 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.7.2
unknown
The Events Manager WordPress plugin was affected by a CSV Injection security vulnerability.
- Affected:
- up to 5.9.7.2
- Fixed in:
- 5.9.7.2
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] <= 7.0.3 (unfixed)
unknown
- Affected:
- up to 7.0.3
- Fix:
- No patched version reported
CVE-2025-6975 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] <= 7.0.3 (unfixed)
unknown
- Affected:
- up to 7.0.3
- Fix:
- No patched version reported
CVE-2025-6970 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] <= 7.0.3 (unfixed)
unknown
- Affected:
- up to 7.0.3
- Fix:
- No patched version reported
CVE-2025-6976 on NVD →
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.6.4.2
unknown
- Affected:
- up to 6.6.4.2
- Fixed in:
- 6.6.4.2
CVE-2025-1249 on NVD →