plugin

Mage Eventpress Vulnerabilities

55 known security issues reported for the Mage Eventpress WordPress plugin. Most recent disclosed Aug 2, 2026.

1 critical 8 high 19 medium

Running Mage Eventpress on your site? Check whether your installed version is affected.

Scan your site free

Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar < 5.3.7 - Authenticated (Contributor+) PHP Object Injection

high

The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to PHP Object Injection in versions up to 5.3.7 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to i...

CVSS:
7.5
Affected:
up to 5.3.7
Fixed in:
5.3.7
Disclosed:
Aug 2, 2026

CVE-2026-16062 on NVD →

Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar < 5.3.7 - Missing Authorization

medium

The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 5.3.7. This makes it possible for authenticated attackers, with contributor-level access and abo...

CVSS:
4.3
Affected:
up to 5.3.7
Fixed in:
5.3.7
Disclosed:
Aug 2, 2026

CVE-2026-16064 on NVD →

Event Booking Manager for WooCommerce <= 5.3.7 - Missing Authorization to Authenticated (Contributor+) Site-Wide Payment Settings Modification via mep_save_payment_settings_modal AJAX Action

medium

The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possi...

CVSS:
4.3
Affected:
up to 5.3.7
Fixed in:
5.3.8
Disclosed:
Jul 28, 2026

CVE-2026-17166 on NVD →

Event Booking Manager for WooCommerce <= 5.3.6 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web...

CVSS:
6.4
Affected:
up to 5.3.6
Fixed in:
5.3.7
Disclosed:
Jul 22, 2026

CVE-2026-16063 on NVD →

Event Booking Manager for WooCommerce <= 5.3.3 - Missing Authorization

medium

The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.3.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 5.3.3
Fixed in:
5.3.4
Disclosed:
May 26, 2026

CVE-2026-45441 on NVD →

Event Booking Manager for WooCommerce <= 5.1.4 - Reflected Cross-Site Scripting

medium

The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

CVSS:
6.1
Affected:
up to 5.1.4
Fixed in:
5.1.5
Disclosed:
Mar 20, 2026

CVE-2026-25361 on NVD →

Event Booking Manager for WooCommerce [mage-eventpress] <= 5.1.1 (unfixed)

unknown

[en] Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.1.1.

Affected:
up to 5.1.1
Fix:
No patched version reported
Disclosed:
Feb 19, 2026

CVE-2026-23549 on NVD →

WpEvently <= 5.1.1 - Unauthenticated PHP Object Injection

high

The WpEvently plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.1.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an...

CVSS:
8.1
Affected:
up to 5.1.1
Fixed in:
5.1.2
Disclosed:
Feb 18, 2026

CVE-2026-23549 on NVD →

WpEvently < 5.1.9 - Unauthenticated Information Exposure

medium

The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 5.1.9 (exclusive). This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 5.1.9
Fixed in:
5.1.9
Disclosed:
Feb 14, 2026

CVE-2026-32354 on NVD →

Event Booking Manager for WooCommerce [mage-eventpress] <= 5.0.8 (unfixed)

unknown

[en] Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.0.8.

Affected:
up to 5.0.8
Fix:
No patched version reported
Disclosed:
Feb 3, 2026

CVE-2026-24954 on NVD →

Event Booking Manager for WooCommerce [mage-eventpress] <= 5.1.1 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in magepeopleteam WpEvently mage-eventpress allows Cross Site Request Forgery.This issue affects WpEvently: from n/a through <= 5.1.1.

Affected:
up to 5.1.1
Fix:
No patched version reported
Disclosed:
Feb 3, 2026

CVE-2026-24942 on NVD →

WpEvently <= 5.0.8 - Authenticated (Contributor+) PHP Object Injection

high

The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.8 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain...

CVSS:
7.5
Affected:
up to 5.0.8
Fixed in:
5.0.9
Disclosed:
Dec 25, 2025

CVE-2026-24954 on NVD →

WpEvently <= 5.1.1 - Cross-Site Request Forgery

medium

The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they...

CVSS:
4.3
Affected:
up to 5.1.1
Fixed in:
5.1.2
Disclosed:
Dec 6, 2025

CVE-2026-24942 on NVD →

WpEvently <= 5.0.4 - Missing Authorization

medium

The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.0.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 5.0.4
Fixed in:
5.0.5
Disclosed:
Dec 4, 2025

CVE-2025-66083 on NVD →

WpEvently <= 5.0.4 - Missing Authorization

medium

The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.0.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 5.0.4
Fixed in:
5.0.5
Disclosed:
Nov 30, 2025

CVE-2025-66082 on NVD →

Event Booking Manager for WooCommerce [mage-eventpress] <= 5.0.4 (unfixed)

unknown

[en] Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 5.0.4.

Affected:
up to 5.0.4
Fix:
No patched version reported
Disclosed:
Nov 21, 2025

CVE-2025-66082 on NVD →

Event Booking Manager for WooCommerce [mage-eventpress] <= 5.0.4 (unfixed)

unknown

[en] Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 5.0.4.

Affected:
up to 5.0.4
Fix:
No patched version reported
Disclosed:
Nov 21, 2025

CVE-2025-66083 on NVD →

Event Booking Manager for WooCommerce [mage-eventpress] < 4.4.9

unknown

[en] Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently allows Object Injection. This issue affects WpEvently: from n/a through 4.4.8.

Affected:
up to 4.4.9
Fixed in:
4.4.9
Disclosed:
Aug 28, 2025

CVE-2025-54742 on NVD →

WpEvently <= 4.4.8 - Authenticated (Contributor+) PHP Object Injection

high

The WpEvently plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.4.8 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable so...

CVSS:
7.5
Affected:
up to 4.4.8
Fixed in:
4.4.9
Disclosed:
Aug 27, 2025

CVE-2025-54742 on NVD →

Event Booking Manager for WooCommerce [mage-eventpress] < 4.4.7

unknown

[en] Missing Authorization vulnerability in magepeopleteam WpEvently allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpEvently: from n/a through 4.4.6.

Affected:
up to 4.4.7
Fixed in:
4.4.7
Disclosed:
Aug 14, 2025

CVE-2025-54705 on NVD →

WpEvently <= 4.4.6 - Missing Authorization

medium

The Event Booking Manager for WooCommerce – WpEvently plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.4.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthor...

CVSS:
4.3
Affected:
up to 4.4.6
Fixed in:
4.4.7
Disclosed:
Jul 30, 2025

CVE-2025-54705 on NVD →

WpEvently <= 4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary...

CVSS:
6.4
Affected:
up to 4.4.2
Fixed in:
4.4.3
Disclosed:
Jun 6, 2025

CVE-2025-5568 on NVD →

Event Booking Manager for WooCommerce [mage-eventpress] < 4.3.7

unknown

[en] Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently allows Object Injection. This issue affects WpEvently: from n/a through 4.3.5.

Affected:
up to 4.3.7
Fixed in:
4.3.7
Disclosed:
Apr 10, 2025

CVE-2025-32145 on NVD →

WpEvently <= 4.3.6 - Authenticated (Contributor+) PHP Object Injection

high

The WpEvently plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.3.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable so...

CVSS:
8.8
Affected:
up to 4.3.6
Fixed in:
4.3.7
Disclosed:
Apr 8, 2025

CVE-2025-32145 on NVD →

WpEvently <= 4.2.9 - Authenticated (Contributor+) Local File Inclusion

high

The WpEvently plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.2.9. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This...

CVSS:
8.8
Affected:
up to 4.2.9
Fixed in:
4.3.0
Disclosed:
Mar 27, 2025

CVE-2025-30895 on NVD →

WpEvently <= 4.2.9 - Missing Authorization

medium

The Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.9. This makes it possible for unauthenticated attackers to perform an unauthoriz...

CVSS:
5.3
Affected:
up to 4.2.9
Fixed in:
4.3.0
Disclosed:
Mar 27, 2025

CVE-2025-30887 on NVD →

Event Booking Manager for WooCommerce [mage-eventpress] < 4.3.0

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in magepeopleteam WpEvently allows PHP Local File Inclusion. This issue affects WpEvently: from n/a through 4.2.9.

Affected:
up to 4.3.0
Fixed in:
4.3.0
Disclosed:
Mar 27, 2025

CVE-2025-30895 on NVD →

Event Booking Manager for WooCommerce [mage-eventpress] < 4.3.0

unknown

[en] Missing Authorization vulnerability in magepeopleteam WpEvently allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpEvently: from n/a through 4.2.9.

Affected:
up to 4.3.0
Fixed in:
4.3.0
Disclosed:
Mar 27, 2025

CVE-2025-30887 on NVD →

Event Booking Manager for WooCommerce [mage-eventpress] < 4.2.6

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagePeople Team Event Manager for WooCommerce allows Stored XSS.This issue affects Event Manager for WooCommerce: from n/a through 4.2.5.

Affected:
up to 4.2.6
Fixed in:
4.2.6
Disclosed:
Oct 24, 2024

CVE-2024-49703 on NVD →

Event Manager for WooCommerce <= 4.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Event Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scr...

CVSS:
6.4
Affected:
up to 4.2.5
Fixed in:
4.2.6
Disclosed:
Oct 21, 2024

CVE-2024-49703 on NVD →

Event Booking Manager for WooCommerce [mage-eventpress] < 4.2.2

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MagePeople Team Event Manager for WooCommerce allows PHP Local File Inclusion.This issue affects Event Manager for WooCommerce: from n/a through 4.2.1.

Affected:
up to 4.2.2
Fixed in:
4.2.2
Disclosed:
Aug 13, 2024

CVE-2024-43138 on NVD →

Event Manager for WooCommerce <= 4.2.1 - Authenticated (Contributor+) Local File Inclusion

critical

The Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.1 via the 'mep_event_template' parameter. This makes it possible for authenticated attackers, with contributor-level access and...

CVSS:
9.9
Affected:
up to 4.2.1
Fixed in:
4.2.2
Disclosed:
Aug 7, 2024

CVE-2024-43138 on NVD →

Appsero <= 2.0.0 - Missing Authorization via handle_optin_optout

medium

The Appsero analytics tool used in several plugins is vulnerable to unauthorized modification of data due to a missing capability check on the handle_optin_optout function in versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to opt-in or opt-out of tracking. This was patched in...

CVSS:
4.3
Affected:
up to 4.1.2
Fixed in:
4.1.3
Disclosed:
Apr 11, 2024

CVE-2024-32110 on NVD →

Event Booking Manager for WooCommerce [mage-eventpress] < 4.1.2

unknown

[en] Deserialization of Untrusted Data vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin.This issue affects Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin: from n/a through 4.1.1.

Affected:
up to 4.1.2
Fixed in:
4.1.2
Disclosed:
Feb 12, 2024

CVE-2024-24796 on NVD →

Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently <= 4.1.1 - Authenticated (Contributor+) PHP Object Injection in mep_event_meta_save

high

The Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.1 via deserialization of untrusted input in the mep_event_meta_save function. This makes it possible for authenticated attackers, with contributor...

CVSS:
8.8
Affected:
up to 4.1.1
Fixed in:
4.1.2
Disclosed:
Jan 31, 2024

CVE-2024-24796 on NVD →

Event Booking Manager for WooCommerce [mage-eventpress] < 3.9.6

unknown

[en] Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.9.5 versions.

Affected:
up to 3.9.6
Fixed in:
3.9.6
Disclosed:
Jul 18, 2023

CVE-2023-36383 on NVD →

Event Booking Manager for WooCommerce [mage-eventpress] < 3.7.8

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.7.7 versions.

Affected:
up to 3.7.8
Fixed in:
3.7.8
Disclosed:
May 25, 2023

CVE-2022-47164 on NVD →

Event Booking Manager for WooCommerce [mage-eventpress] < 3.8.7

unknown

[en] Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce <= 3.8.6. versions.

Affected:
up to 3.8.7
Fixed in:
3.8.7
Disclosed:
Mar 23, 2023

CVE-2023-28422 on NVD →

Event Manager for WooCommerce <= 3.8.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'mep_get_option' function

medium

The Event Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mep_get_option' function in versions up to, and including, 3.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level access, an...

CVSS:
4.4
Affected:
up to 3.8.6
Fixed in:
3.8.7
Disclosed:
Mar 20, 2023

CVE-2023-28422 on NVD →

Event Manager for WooCommerce <= 3.7.7 - Cross-Site Request Forgery leading to Uninstall Form Submission

medium

The Event Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.7. This is due to missing or incorrect nonce validation on the 'uninstall_reason_submission' function. This makes it possible for unauthenticated attackers to submit plugin uninstall...

CVSS:
4.3
Affected:
up to 3.7.7
Fixed in:
3.7.8
Disclosed:
Mar 16, 2023

CVE-2022-47164 on NVD →

Event Booking Manager for WooCommerce [mage-eventpress] < 3.8.0

unknown

[en] The Event Manager and Tickets Selling Plugin for WooCommerce WordPress plugin before 3.8.0 does not validate and escape some of its post meta before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Affected:
up to 3.8.0
Fixed in:
3.8.0
Disclosed:
Feb 6, 2023

CVE-2023-0144 on NVD →

Event Manager and Tickets Selling Plugin for WooCommerce <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Event Manager and Tickets Selling Plugin for WooCommerce is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 3.7.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with co...

CVSS:
6.4
Affected:
up to 3.7.9
Fixed in:
3.8.0
Disclosed:
Jan 10, 2023

CVE-2023-0144 on NVD →

Event Booking Manager for WooCommerce [mage-eventpress] < 3.5.8

unknown

[en] The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which could allow users with a role as low as contributor to perform SQL Injection attacks

Affected:
up to 3.5.8
Fixed in:
3.5.8
Disclosed:
Mar 14, 2022

CVE-2022-0478 on NVD →

Event Manager and Tickets Selling for WooCommerce < 3.5.8 - SQL Injection

high

The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which could allow users with a role as low as contributor to perform SQL Injection attacks

CVSS:
8.8
Affected:
up to 3.5.8
Fixed in:
3.5.8
Disclosed:
Feb 21, 2022

CVE-2022-0478 on NVD →

Event Manager and Tickets Selling Plugin for WooCommerce < 3.5.3 - Arbitrary Settings Change

medium

The Event Manager and Tickets Selling Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary settings reset via the mep_wl_ajax_license_activate and mep_wl_ajax_license_deactivate functions in versions before 3.5.3. This is due to a missing capabilities check on these functions. This makes it possible f...

CVSS:
6.5
Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
Nov 3, 2021

Event Manager and Tickets Selling Plugin for WooCommerce < 3.5.3 - Missing Authorization

medium

The Event Manager and Tickets Selling Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary template import in versions before 3.5.3 via the mep_import_ajax_template function. This is due to a missing capability check on this function. This makes it possible for unauthenticated attackers to arbitrarily...

CVSS:
5.3
Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
Nov 3, 2021

Event Booking Manager for WooCommerce [mage-eventpress] < 3.5.3

unknown

Unauthenticated Arbitrary Options Reset vulnerability discovered by WPScanTeam in WordPress Event Manager for WooCommerce plugin (versions <= 3.5.1).

Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
Nov 3, 2021

Event Booking Manager for WooCommerce [mage-eventpress] < 3.5.3

unknown

Unauthenticated Arbitrary Elementor Template Import vulnerability discovered by WPScanTeam in WordPress Event Manager for WooCommerce plugin (versions <= 3.5.1).

Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
Nov 3, 2021

Event Booking Manager for WooCommerce [mage-eventpress] < 3.5.3

unknown

The Event Manager and Tickets Selling Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary settings reset via the mep_wl_ajax_license_activate and mep_wl_ajax_license_deactivate functions in versions before 3.5.3. This is due to a missing capabilities check on these functions. This makes it possible f...

Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
Nov 3, 2021

Event Booking Manager for WooCommerce [mage-eventpress] < 3.5.3

unknown

The Event Manager and Tickets Selling Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary template import in versions before 3.5.3 via the mep_import_ajax_template function. This is due to a missing capability check on this function. This makes it possible for unauthenticated attackers to arbitrarily...

Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
Nov 3, 2021

Event Booking Manager for WooCommerce [mage-eventpress] < 4.4.3

unknown
Affected:
up to 4.4.3
Fixed in:
4.4.3

CVE-2025-5568 on NVD →

Event Booking Manager for WooCommerce [mage-eventpress] < 4.1.3

unknown
Affected:
up to 4.1.3
Fixed in:
4.1.3

CVE-2024-32110 on NVD →

Event Booking Manager for WooCommerce [mage-eventpress] < 4.1.2

unknown

Update the WordPress Event Manager for WooCommerce plugin to the latest available version (at least 4.1.2). Ngô Thiên An (ancorn_ from VNPT-VCI) discovered and reported this PHP Object Injection vulnerability in WordPress Event Manager for WooCommerce Plugin. This could allow a malicious actor to execute code injection...

Affected:
up to 4.1.2
Fixed in:
4.1.2

Event Booking Manager for WooCommerce [mage-eventpress] < 3.5.3

unknown

The plugin has two AJAX actions, mep_wl_ajax_license_activate and mep_wl_ajax_license_deactivate, which are available to both unauthenticated and authenticated users, and are lacking any authorisation, CSRF as well as checks to ensure that the options to be updated belong to the plugin. As a result, unauthenticated use...

Affected:
up to 3.5.3
Fixed in:
3.5.3

Event Booking Manager for WooCommerce [mage-eventpress] < 3.5.3

unknown

The mep_import_ajax_template AJAX action of the plugin, available to both unauthenticated and authenticated users, is lacking any authorisation and CSRF checks. As a result, unauthenticated user can import arbitrary Elementor template to the blog

Affected:
up to 3.5.3
Fixed in:
3.5.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database