plugin

Events Manager Vulnerabilities

86 known security issues reported for the Events Manager WordPress plugin. Most recent disclosed Aug 24, 2026.

1 critical 8 high 35 medium

Running Events Manager on your site? Check whether your installed version is affected.

Scan your site free

Events Manager <= 7.4.0.1 - Reflected Cross-Site Scripting via 'header_format' Parameter

medium

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'header_format' parameter in all versions up to, and including, 7.4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacker...

CVSS:
6.1
Affected:
up to 7.4.0.1
Fixed in:
7.4.1
Disclosed:
Aug 24, 2026

CVE-2026-17089 on NVD →

Events Manager <= 7.3.7.4 - Authenticated (Administrator+) Local File Inclusion via 'dbem_data[updates]' Array Keys

medium

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.3.7.4 via the em_options_save function. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arb...

CVSS:
6.6
Affected:
up to 7.3.7.4
Fixed in:
7.4
Disclosed:
Aug 24, 2026

CVE-2026-14280 on NVD →

Events Manager <= 7.4.0 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'status', 'private', and 'private_only' Parameters

medium

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to vie...

CVSS:
5.3
Affected:
up to 7.4.0
Fixed in:
7.4.1
Disclosed:
Aug 24, 2026

CVE-2026-10627 on NVD →

Events Manager <= 7.4.0 - Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter in Event/Location Duplicate Action

medium

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to generic SQL Injection via Stored 'meta_key' via Event/Location Duplicate Action in all versions up to, and including, 7.4.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on...

CVSS:
6.5
Affected:
up to 7.4.0
Fixed in:
7.4.1
Disclosed:
Aug 24, 2026

CVE-2026-15023 on NVD →

Events Manager <= 7.4.0 - Unauthenticated Privilege Escalation

high

The Events Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 7.4.0. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for unauthenticated attackers to elevate their privileges beyond those intended for their...

CVSS:
7.3
Affected:
up to 7.4.0
Fixed in:
7.4.1
Disclosed:
Aug 10, 2026

CVE-2026-18366 on NVD →

Events Manager <= 7.4.0 - Authenticated (Subscriber+) SQL Injection

medium

The Events Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.4.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and ab...

CVSS:
6.5
Affected:
up to 7.4.0
Fixed in:
7.4.1
Disclosed:
Aug 10, 2026

CVE-2026-18057 on NVD →

Events Manager – Calendar, Bookings, Tickets, and more! <= 7.4.2 - Unauthenticated Stored Cross-Site Scripting

high

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
7.2
Affected:
up to 7.4.2
Fix:
No patched version reported
Disclosed:
Aug 4, 2026

CVE-2026-66457 on NVD →

Events Manager <= 7.3 - Unauthenticated Pending Upload Disclosure

medium

The Events Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.3. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 7.3
Fixed in:
7.4
Disclosed:
Jul 30, 2026

CVE-2026-18050 on NVD →

Events Manager – Calendar, Bookings, Tickets, and more! <= 7.3.6 - Unauthenticated PHP Object Injection

high

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 7.3.6 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnera...

CVSS:
8.1
Affected:
up to 7.3.6
Fixed in:
7.3.7
Disclosed:
Jul 8, 2026

CVE-2026-57713 on NVD →

Events Manager <= 7.3.6 - Unauthenticated SQL Injection

high

The Events Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries i...

CVSS:
7.5
Affected:
up to 7.3.6
Fixed in:
7.3.7
Disclosed:
Jul 1, 2026

CVE-2026-12987 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 7.2.3

unknown

[en] The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list_grouped' shortcode in all versions up to, and including, 7.2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This m...

Affected:
up to 7.2.3
Fixed in:
7.2.3
Disclosed:
Dec 18, 2025

CVE-2025-12976 on NVD →

Events Manager <= 7.2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'events_list_grouped' Shortcode

medium

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list_grouped' shortcode in all versions up to, and including, 7.2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes...

CVSS:
6.4
Affected:
up to 7.2.2.1
Fixed in:
7.2.3
Disclosed:
Dec 17, 2025

CVE-2025-12976 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 7.2.2.3

unknown

[en] The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 7.2.2.2 via the 'get_location' action due to insufficient restrictions on which locations can be included. This makes it possible for unauthenticated attacker...

Affected:
up to 7.2.2.3
Fixed in:
7.2.2.3
Disclosed:
Dec 12, 2025

CVE-2025-12408 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 7.2.2.3

unknown

[en] The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.2.2. This is due to missing or incorrect nonce validation on the 'location_delete' action. This makes it possible for unauthenticated attackers to d...

Affected:
up to 7.2.2.3
Fixed in:
7.2.2.3
Disclosed:
Dec 12, 2025

CVE-2025-12407 on NVD →

Events Manager – Calendar, Bookings, Tickets, and more! <= 7.2.2.2 - Cross-Site Request Forgery to Location Deletion

medium

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.2.2. This is due to missing or incorrect nonce validation on the 'location_delete' action. This makes it possible for unauthenticated attackers to delete...

CVSS:
4.3
Affected:
up to 7.2.2.2
Fixed in:
7.2.2.3
Disclosed:
Dec 11, 2025

CVE-2025-12407 on NVD →

Events Manager <= 7.2.2.2 - Unauthenticated Information Exposure

medium

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 7.2.2.2 via the 'get_location' action due to insufficient restrictions on which locations can be included. This makes it possible for unauthenticated attackers to...

CVSS:
5.3
Affected:
up to 7.2.2.2
Fixed in:
7.2.2.3
Disclosed:
Dec 11, 2025

CVE-2025-12408 on NVD →

Events Manager <= 7.0.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes

medium

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authen...

CVSS:
6.4
Affected:
up to 6.6.4.4, 7.0.1 – 7.0.3
Fixed in:
6.6.5
Disclosed:
Jul 9, 2025

CVE-2025-6976 on NVD →

Events Manager <= 7.0.3 - Unauthenticated SQL Injection via `orderby` Parameter

high

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Th...

CVSS:
7.5
Affected:
up to 6.6.4.4, 7.0.1 – 7.0.3
Fixed in:
6.6.5
Disclosed:
Jul 9, 2025

CVE-2025-6970 on NVD →

Event Manager <= 7.0.3 - Reflected Cross-Site Scripting via `calendar_header` Parameter

medium

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘calendar_header’ parameter in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacker...

CVSS:
6.1
Affected:
up to 6.6.4.4, 7.0.1 – 7.0.3
Fixed in:
6.6.5
Disclosed:
Jul 9, 2025

CVE-2025-6975 on NVD →

Events Manager – Calendar, Bookings, Tickets, and more! <= 6.6.4.1 - Missing Authorization

medium

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.6.4.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 6.6.4.1
Fixed in:
6.6.4.2
Disclosed:
Feb 26, 2025

CVE-2025-1249 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 6.6.4

unknown

[en] The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL q...

Affected:
up to 6.6.4
Fixed in:
6.6.4
Disclosed:
Feb 21, 2025

CVE-2024-11260 on NVD →

Events Manager – Calendar, Bookings, Tickets, and more! <= 6.6.3 - Unauthenticated SQL Injection via Event Status Parameter

high

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query....

CVSS:
7.5
Affected:
up to 6.6.3
Fixed in:
6.6.4
Disclosed:
Feb 20, 2025

CVE-2024-11260 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.9

unknown

[en] The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers t...

Affected:
up to 6.4.9
Fixed in:
6.4.9
Disclosed:
Jun 29, 2024

CVE-2024-5889 on NVD →

Events Manager <= 6.4.8 - Reflected Cross-Site Scripting

medium

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inj...

CVSS:
6.1
Affected:
up to 6.4.8
Fixed in:
6.4.9
Disclosed:
Jun 28, 2024

CVE-2024-5889 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.8

unknown

[en] The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' shortcodes in all versions up to, and including, 6.4.7.3 due to insufficient input sanitization and output escaping on user suppli...

Affected:
up to 6.4.8
Fixed in:
6.4.8
Disclosed:
Jun 12, 2024

CVE-2024-3492 on NVD →

Events Manager – Calendar, Bookings, Tickets, and more! <= 6.4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via event, location, and event_category Shortcodes

medium

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' shortcodes in all versions up to, and including, 6.4.7.3 due to insufficient input sanitization and output escaping on user supplied at...

CVSS:
6.4
Affected:
up to 6.4.7.3
Fixed in:
6.4.8
Disclosed:
Jun 11, 2024

CVE-2024-3492 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.7

unknown

[en] Missing Authorization vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.6.4.

Affected:
up to 6.4.7
Fixed in:
6.4.7
Disclosed:
Jun 9, 2024

CVE-2024-30515 on NVD →

Events Manager <= 6.4.7.1 - Cross-Site Request Forgery

medium

The Events Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.7.1. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site a...

CVSS:
4.3
Affected:
up to 6.4.7.1
Fixed in:
6.4.7.2
Disclosed:
Mar 28, 2024

CVE-2024-30421 on NVD →

Events Manager <= 6.4.6.4 - Missing Authorization

medium

The Events Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 6.4.6.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.

CVSS:
4.3
Affected:
up to 6.4.6.4
Fixed in:
6.4.7
Disclosed:
Mar 28, 2024

CVE-2024-30515 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.7.2

unknown

[en] The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.7.1. This is due to missing or incorrect nonce validation on several actions. This makes it possible for unauthenticated attackers to modify booking...

Affected:
up to 6.4.7.2
Fixed in:
6.4.7.2
Disclosed:
Mar 28, 2024

CVE-2024-2110 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.7.2

unknown

[en] The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the physical location value in all versions up to, and including, 6.4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...

Affected:
up to 6.4.7.2
Fixed in:
6.4.7.2
Disclosed:
Mar 28, 2024

CVE-2024-2111 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.7.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.7.1.

Affected:
up to 6.4.7.2
Fixed in:
6.4.7.2
Disclosed:
Mar 28, 2024

CVE-2024-30421 on NVD →

Events Manager <= 6.4.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the physical location value in all versions up to, and including, 6.4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with...

CVSS:
6.4
Affected:
up to 6.4.7.1
Fixed in:
6.4.7.2
Disclosed:
Mar 27, 2024

CVE-2024-2111 on NVD →

Events Manager <= 6.4.7.1 - Cross-Site Request Forgery

medium

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.7.1. This is due to missing or incorrect nonce validation on several actions. This makes it possible for unauthenticated attackers to modify booking stat...

CVSS:
4.3
Affected:
up to 6.4.7.1
Fixed in:
6.4.7.2
Disclosed:
Mar 27, 2024

CVE-2024-2110 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.7

unknown

[en] The Events Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.4.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to in...

Affected:
up to 6.4.7
Fixed in:
6.4.7
Disclosed:
Mar 13, 2024

CVE-2024-0614 on NVD →

Events Manager <= 6.4.6.4 - Authenticated(Administator+) Stored Cross-Site Scripting via settings

medium

The Events Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.4.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...

CVSS:
4.4
Affected:
up to 6.4.6.4
Fixed in:
6.4.7
Disclosed:
Feb 28, 2024

CVE-2024-0614 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.6

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager allows Reflected XSS.This issue affects Events Manager: from n/a through 6.4.5.

Affected:
up to 6.4.6
Fixed in:
6.4.6
Disclosed:
Nov 30, 2023

CVE-2023-48326 on NVD →

Events Manager <= 6.4.5 - Reflected Cross-Site Scripting

medium

The Events Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions up to, and including, 6.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...

CVSS:
6.1
Affected:
up to 6.4.5
Fixed in:
6.4.6
Disclosed:
Nov 23, 2023

CVE-2023-48326 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.8

unknown

[en] The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues

Affected:
up to 5.9.8
Fixed in:
5.9.8
Disclosed:
Dec 1, 2021

CVE-2020-35037 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.8

unknown

[en] The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection

Affected:
up to 5.9.8
Fixed in:
5.9.8
Disclosed:
Dec 1, 2021

CVE-2020-35012 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.8

unknown

SQL Injection (SQLi) vulnerability found by Antony Garand in WordPress Events Manager plugin (versions <= 5.9.7.3).

Affected:
up to 5.9.8
Fixed in:
5.9.8
Disclosed:
Nov 30, 2020

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.8

unknown

Cross-Site Scripting (XSS) vulnerability found by Jakob Wierzba in WordPress Events Manager plugin (versions <= 5.9.7.3).

Affected:
up to 5.9.8
Fixed in:
5.9.8
Disclosed:
Nov 30, 2020

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.8.2

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Nguyen Van Khanh in WordPress Events Manager plugin (versions <= 5.9.8.1).

Affected:
up to 5.9.8.2
Fixed in:
5.9.8.2
Disclosed:
Nov 25, 2020

Events Manager <= 5.9.7.3 - Admin+ SQL Injection

high

The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection

CVSS:
7.2
Affected:
up to 5.9.7.3
Fixed in:
5.9.8
Disclosed:
Jun 7, 2020

CVE-2020-35012 on NVD →

Events Manager <= 5.9.7.3 - Cross-Site Scripting

medium

The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues

CVSS:
6.1
Affected:
up to 5.9.7.3
Fixed in:
5.9.8
Disclosed:
Jun 7, 2020

CVE-2020-35037 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.7.2

unknown

CSV Injection vulnerability found by Vishnupriya Ilango in WordPress Events Manager plugin (versions <= 5.9.7.1).

Affected:
up to 5.9.7.2
Fixed in:
5.9.7.2
Disclosed:
Feb 7, 2020

Events Manager < 5.9.7.2 & Events Manager Pro < 2.6.7.2 - Unauthenticated CSV Injection

high

The Events Manager Pro, versions up to 2.6.7.2, and Events Manager, versions up to 5.9.7.2, plugins for WordPress are vulnerable to CSV Injection. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a lo...

CVSS:
7.1
Affected:
up to 5.9.7.2
Fixed in:
5.9.7.2
Disclosed:
Feb 6, 2020

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.7.2

unknown

The Events Manager Pro, versions up to 2.6.7.2, and Events Manager, versions up to 5.9.7.2, plugins for WordPress are vulnerable to CSV Injection. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a lo...

Affected:
up to 5.9.7.2
Fixed in:
5.9.7.2
Disclosed:
Feb 6, 2020

Events Manager <= 5.9.7.1 - CSV Injection

medium

The Events Manager plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 5.9.7.1 through the use of the Microsoft Excel DDE function. This allows low-privileged attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded...

CVSS:
5.5
Affected:
up to 5.9.7.1
Fixed in:
5.9.7.2
Disclosed:
Feb 5, 2020

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.7.2

unknown

The Events Manager plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 5.9.7.1 through the use of the Microsoft Excel DDE function. This allows low-privileged attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded...

Affected:
up to 5.9.7.2
Fixed in:
5.9.7.2
Disclosed:
Feb 5, 2020

Events Manager <= 5.9.5 - Authenticated Stored Cross-Site Scripting

medium

The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and events_map) provided by the plugin.

CVSS:
6.4
Affected:
up to 5.9.5
Fixed in:
5.9.6
Disclosed:
Oct 16, 2019

CVE-2019-16523 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.6

unknown

[en] The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and events_map) provided by the plugin.

Affected:
up to 5.9.6
Fixed in:
5.9.6
Disclosed:
Oct 16, 2019

CVE-2019-16523 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.5.2

unknown

[en] The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.

Affected:
up to 5.5.2
Fixed in:
5.5.2
Disclosed:
Aug 22, 2019

CVE-2013-7477 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.1.7

unknown

[en] The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links.

Affected:
up to 5.1.7
Fixed in:
5.1.7
Disclosed:
Aug 22, 2019

CVE-2012-6716 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.5

unknown

[en] The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.

Affected:
up to 5.5
Fixed in:
5.5
Disclosed:
Aug 22, 2019

CVE-2013-7478 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.3.6.1

unknown

[en] The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.

Affected:
up to 5.3.6.1
Fixed in:
5.3.6.1
Disclosed:
Aug 22, 2019

CVE-2013-7480 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.3.9

unknown

[en] The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.

Affected:
up to 5.3.9
Fixed in:
5.3.9
Disclosed:
Aug 22, 2019

CVE-2013-7479 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.6

unknown

[en] The events-manager plugin before 5.6 for WordPress has XSS.

Affected:
up to 5.6
Fixed in:
5.6
Disclosed:
Aug 13, 2019

CVE-2015-9297 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.5.7.1

unknown

[en] The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS.

Affected:
up to 5.5.7.1
Fixed in:
5.5.7.1
Disclosed:
Aug 13, 2019

CVE-2015-9299 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.6

unknown

[en] The events-manager plugin before 5.6 for WordPress has code injection.

Affected:
up to 5.6
Fixed in:
5.6
Disclosed:
Aug 13, 2019

CVE-2015-9298 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.5.7

unknown

[en] The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues.

Affected:
up to 5.5.7
Fixed in:
5.5.7
Disclosed:
Aug 13, 2019

CVE-2015-9300 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.5

unknown

[en] The Events Manager plugin 5.9.4 for WordPress has XSS via the dbem_event_reapproved_email_body parameter to the wp-admin/edit.php?post_type=event&page=events-manager-options URI.

Affected:
up to 5.9.5
Fixed in:
5.9.5
Disclosed:
Apr 12, 2019

CVE-2018-13137 on NVD →

Events Manager <= 5.9.4 - Cross-Site Scripting

medium

The Events Manager plugin 5.9.4 for WordPress has XSS via the dbem_event_reapproved_email_body parameter to the wp-admin/edit.php?post_type=event&page=events-manager-options URI.

CVSS:
4.8
Affected:
up to 5.9.4
Fixed in:
5.9.5
Disclosed:
Jul 18, 2018

CVE-2018-13137 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.9

unknown

[en] Cross-site scripting vulnerability in Events Manager plugin prior to version 5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected:
up to 5.9
Fixed in:
5.9
Disclosed:
May 14, 2018

CVE-2018-0576 on NVD →

Events Manager <= 5.8.1.3 - Stored Cross-Site Scripting

medium

Cross-site scripting vulnerability in Events Manager plugin prior to version 5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS:
5.4
Affected:
up to 5.9
Fixed in:
5.9
Disclosed:
Apr 27, 2018

CVE-2018-0576 on NVD →

Events Manager <= 5.8.1.1 - Cross-Site Scripting

medium

The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature.

CVSS:
6.4
Affected:
up to 5.8.1.2
Fixed in:
5.8.1.2
Disclosed:
Mar 26, 2018

CVE-2018-9020 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.8.1.2

unknown

[en] The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature.

Affected:
up to 5.8.1.2
Fixed in:
5.8.1.2
Disclosed:
Mar 26, 2018

CVE-2018-9020 on NVD →

Events Manager <= 5.5.7.1 - Code Injection

critical

The Events Manager plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 5.5.7.1. This makes it possible for attackers to inject code onto the server and potentially execute it.

CVSS:
9.8
Affected:
up to 5.6
Fixed in:
5.6
Disclosed:
Aug 10, 2015

CVE-2015-9298 on NVD →

Events Manager <= 5.5.7.1 - Cross-Site Scripting

medium

The events-manager plugin before 5.6 for WordPress has XSS.

CVSS:
6.1
Affected:
up to 5.6
Fixed in:
5.6
Disclosed:
Aug 10, 2015

CVE-2015-9297 on NVD →

Events Manager < 5.5.7.1 - Cross-Site Scripting

medium

The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS via the dbem_event_reapproved_email_body parameter.

CVSS:
6.1
Affected:
up to 5.5.7.1
Fixed in:
5.5.7.1
Disclosed:
Jun 4, 2015

CVE-2015-9299 on NVD →

Events Manager < 5.5.7 - Cross-Site Scripting

medium

The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues.

CVSS:
6.1
Affected:
up to 5.5.7
Fixed in:
5.5.7
Disclosed:
May 23, 2015

CVE-2015-9300 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.5.2

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 5.5.2
Fixed in:
5.5.2
Disclosed:
May 15, 2015

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.3.9

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 5.3.9
Fixed in:
5.3.9
Disclosed:
May 15, 2015

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.3.6

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 5.3.6
Fixed in:
5.3.6
Disclosed:
May 15, 2015

Events Manager <= 5.5.1 - Multiple Cross-Site Scripting

medium

The Events Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 5.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 5.5.1
Fixed in:
5.5.2
Disclosed:
Aug 1, 2014

CVE-2013-7477 on NVD →

Events Manager < 5.3.5 & Events Manager Pro < 2.2.9 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) scope parameter to index.php; (2) user_name, (3) dbem_phone, (4) user_email, or (5) booking_com...

CVSS:
6.1
Affected:
up to 5.3.5
Fixed in:
5.3.5
Disclosed:
Aug 1, 2014

CVE-2013-1407 on NVD →

Events Manager < 5.3.9 - Cross-Site Scripting

medium

The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.

CVSS:
6.1
Affected:
up to 5.3.9
Fixed in:
5.3.9
Disclosed:
Aug 1, 2014

CVE-2013-7479 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.3.5

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) scope parameter to index.php; (2) user_name, (3) dbem_phone, (4) user_email, or (5) bookin...

Affected:
up to 5.3.5
Fixed in:
5.3.5
Disclosed:
May 13, 2014

CVE-2013-1407 on NVD →

Events Manager < 5.5 - Cross-Site Scripting

medium

The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.

CVSS:
6.1
Affected:
up to 5.5
Fixed in:
5.5
Disclosed:
Aug 14, 2013

CVE-2013-7478 on NVD →

Events Manager <= 5.3.6 - Multiple Cross-Site Scripting

medium

The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.

CVSS:
6.1
Affected:
up to 5.3.6
Fixed in:
5.3.6.1
Disclosed:
Feb 27, 2013

CVE-2013-7480 on NVD →

Events Manager < 5.1.7 - Cross-Site Scripting

medium

The Events Manager plugin before 5.1.7 for WordPress has XSS via JSON call links.

CVSS:
6.1
Affected:
up to 5.1.7
Fixed in:
5.1.7
Disclosed:
May 22, 2012

CVE-2012-6716 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.7.2

unknown

The Events Manager WordPress plugin was affected by a CSV Injection security vulnerability.

Affected:
up to 5.9.7.2
Fixed in:
5.9.7.2

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] <= 7.0.3 (unfixed)

unknown
Affected:
up to 7.0.3
Fix:
No patched version reported

CVE-2025-6975 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] <= 7.0.3 (unfixed)

unknown
Affected:
up to 7.0.3
Fix:
No patched version reported

CVE-2025-6970 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] <= 7.0.3 (unfixed)

unknown
Affected:
up to 7.0.3
Fix:
No patched version reported

CVE-2025-6976 on NVD →

Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 6.6.4.2

unknown
Affected:
up to 6.6.4.2
Fixed in:
6.6.4.2

CVE-2025-1249 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database