plugin

Events Manager Pro Vulnerabilities

6 known security issues reported for the Events Manager Pro WordPress plugin. Most recent disclosed Feb 7, 2020.

1 high 1 medium

Running Events Manager Pro on your site? Check whether your installed version is affected.

Scan your site free

Events Manager Pro [events-manager-pro] < 2.6.7.2

unknown

CSV Injection vulnerability found by Vishnupriya Ilango in WordPress Events Manager Pro plugin (versions <= 2.6.7.1).

Affected:
up to 2.6.7.2
Fixed in:
2.6.7.2
Disclosed:
Feb 7, 2020

Events Manager < 5.9.7.2 & Events Manager Pro < 2.6.7.2 - Unauthenticated CSV Injection

high

The Events Manager Pro, versions up to 2.6.7.2, and Events Manager, versions up to 5.9.7.2, plugins for WordPress are vulnerable to CSV Injection. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a lo...

CVSS:
7.1
Affected:
up to 2.6.7.2
Fixed in:
2.6.7.2
Disclosed:
Feb 6, 2020

Events Manager Pro [events-manager-pro] < 2.6.7.2

unknown

The Events Manager Pro, versions up to 2.6.7.2, and Events Manager, versions up to 5.9.7.2, plugins for WordPress are vulnerable to CSV Injection. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a lo...

Affected:
up to 2.6.7.2
Fixed in:
2.6.7.2
Disclosed:
Feb 6, 2020

Events Manager < 5.3.5 & Events Manager Pro < 2.2.9 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) scope parameter to index.php; (2) user_name, (3) dbem_phone, (4) user_email, or (5) booking_com...

CVSS:
6.1
Affected:
up to 2.2.9
Fixed in:
2.2.9
Disclosed:
Aug 1, 2014

CVE-2013-1407 on NVD →

Events Manager Pro [events-manager-pro] < 2.2.9

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) scope parameter to index.php; (2) user_name, (3) dbem_phone, (4) user_email, or (5) bookin...

Affected:
up to 2.2.9
Fixed in:
2.2.9
Disclosed:
May 13, 2014

CVE-2013-1407 on NVD →

Events Manager Pro [events-manager-pro] < 2.6.7.2

unknown

The events-manager-pro WordPress plugin was affected by a CSV Injection security vulnerability.

Affected:
up to 2.6.7.2
Fixed in:
2.6.7.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database