Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar < 5.3.7 - Authenticated (Contributor+) PHP Object Injection
high
The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to PHP Object Injection in versions up to 5.3.7 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to i...
- CVSS:
- 7.5
- Affected:
- up to 5.3.7
- Fixed in:
- 5.3.7
- Disclosed:
- Aug 2, 2026
CVE-2026-16062 on NVD →
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar < 5.3.7 - Missing Authorization
medium
The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 5.3.7. This makes it possible for authenticated attackers, with contributor-level access and abo...
- CVSS:
- 4.3
- Affected:
- up to 5.3.7
- Fixed in:
- 5.3.7
- Disclosed:
- Aug 2, 2026
CVE-2026-16064 on NVD →
Event Booking Manager for WooCommerce <= 5.3.7 - Missing Authorization to Authenticated (Contributor+) Site-Wide Payment Settings Modification via mep_save_payment_settings_modal AJAX Action
medium
The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possi...
- CVSS:
- 4.3
- Affected:
- up to 5.3.7
- Fixed in:
- 5.3.8
- Disclosed:
- Jul 28, 2026
CVE-2026-17166 on NVD →
Event Booking Manager for WooCommerce <= 5.3.6 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web...
- CVSS:
- 6.4
- Affected:
- up to 5.3.6
- Fixed in:
- 5.3.7
- Disclosed:
- Jul 22, 2026
CVE-2026-16063 on NVD →
Event Booking Manager for WooCommerce <= 5.3.3 - Missing Authorization
medium
The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.3.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 5.3.3
- Fixed in:
- 5.3.4
- Disclosed:
- May 26, 2026
CVE-2026-45441 on NVD →
Event Booking Manager for WooCommerce <= 5.1.4 - Reflected Cross-Site Scripting
medium
The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- CVSS:
- 6.1
- Affected:
- up to 5.1.4
- Fixed in:
- 5.1.5
- Disclosed:
- Mar 20, 2026
CVE-2026-25361 on NVD →
Event Booking Manager for WooCommerce [mage-eventpress] <= 5.1.1 (unfixed)
unknown
[en] Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.1.1.
- Affected:
- up to 5.1.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-23549 on NVD →
WpEvently <= 5.1.1 - Unauthenticated PHP Object Injection
high
The WpEvently plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.1.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an...
- CVSS:
- 8.1
- Affected:
- up to 5.1.1
- Fixed in:
- 5.1.2
- Disclosed:
- Feb 18, 2026
CVE-2026-23549 on NVD →
WpEvently < 5.1.9 - Unauthenticated Information Exposure
medium
The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 5.1.9 (exclusive). This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 5.1.9
- Fixed in:
- 5.1.9
- Disclosed:
- Feb 14, 2026
CVE-2026-32354 on NVD →
Event Booking Manager for WooCommerce [mage-eventpress] <= 5.0.8 (unfixed)
unknown
[en] Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.0.8.
- Affected:
- up to 5.0.8
- Fix:
- No patched version reported
- Disclosed:
- Feb 3, 2026
CVE-2026-24954 on NVD →
Event Booking Manager for WooCommerce [mage-eventpress] <= 5.1.1 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in magepeopleteam WpEvently mage-eventpress allows Cross Site Request Forgery.This issue affects WpEvently: from n/a through <= 5.1.1.
- Affected:
- up to 5.1.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 3, 2026
CVE-2026-24942 on NVD →
WpEvently <= 5.0.8 - Authenticated (Contributor+) PHP Object Injection
high
The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.8 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain...
- CVSS:
- 7.5
- Affected:
- up to 5.0.8
- Fixed in:
- 5.0.9
- Disclosed:
- Dec 25, 2025
CVE-2026-24954 on NVD →
WpEvently <= 5.1.1 - Cross-Site Request Forgery
medium
The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they...
- CVSS:
- 4.3
- Affected:
- up to 5.1.1
- Fixed in:
- 5.1.2
- Disclosed:
- Dec 6, 2025
CVE-2026-24942 on NVD →
WpEvently <= 5.0.4 - Missing Authorization
medium
The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.0.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 5.0.4
- Fixed in:
- 5.0.5
- Disclosed:
- Dec 4, 2025
CVE-2025-66083 on NVD →
WpEvently <= 5.0.4 - Missing Authorization
medium
The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.0.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 5.0.4
- Fixed in:
- 5.0.5
- Disclosed:
- Nov 30, 2025
CVE-2025-66082 on NVD →
Event Booking Manager for WooCommerce [mage-eventpress] <= 5.0.4 (unfixed)
unknown
[en] Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 5.0.4.
- Affected:
- up to 5.0.4
- Fix:
- No patched version reported
- Disclosed:
- Nov 21, 2025
CVE-2025-66082 on NVD →
Event Booking Manager for WooCommerce [mage-eventpress] <= 5.0.4 (unfixed)
unknown
[en] Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 5.0.4.
- Affected:
- up to 5.0.4
- Fix:
- No patched version reported
- Disclosed:
- Nov 21, 2025
CVE-2025-66083 on NVD →
Event Booking Manager for WooCommerce [mage-eventpress] < 4.4.9
unknown
[en] Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently allows Object Injection. This issue affects WpEvently: from n/a through 4.4.8.
- Affected:
- up to 4.4.9
- Fixed in:
- 4.4.9
- Disclosed:
- Aug 28, 2025
CVE-2025-54742 on NVD →
WpEvently <= 4.4.8 - Authenticated (Contributor+) PHP Object Injection
high
The WpEvently plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.4.8 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable so...
- CVSS:
- 7.5
- Affected:
- up to 4.4.8
- Fixed in:
- 4.4.9
- Disclosed:
- Aug 27, 2025
CVE-2025-54742 on NVD →
Event Booking Manager for WooCommerce [mage-eventpress] < 4.4.7
unknown
[en] Missing Authorization vulnerability in magepeopleteam WpEvently allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpEvently: from n/a through 4.4.6.
- Affected:
- up to 4.4.7
- Fixed in:
- 4.4.7
- Disclosed:
- Aug 14, 2025
CVE-2025-54705 on NVD →
WpEvently <= 4.4.6 - Missing Authorization
medium
The Event Booking Manager for WooCommerce – WpEvently plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.4.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthor...
- CVSS:
- 4.3
- Affected:
- up to 4.4.6
- Fixed in:
- 4.4.7
- Disclosed:
- Jul 30, 2025
CVE-2025-54705 on NVD →
WpEvently <= 4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary...
- CVSS:
- 6.4
- Affected:
- up to 4.4.2
- Fixed in:
- 4.4.3
- Disclosed:
- Jun 6, 2025
CVE-2025-5568 on NVD →
Event Booking Manager for WooCommerce [mage-eventpress] < 4.3.7
unknown
[en] Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently allows Object Injection. This issue affects WpEvently: from n/a through 4.3.5.
- Affected:
- up to 4.3.7
- Fixed in:
- 4.3.7
- Disclosed:
- Apr 10, 2025
CVE-2025-32145 on NVD →
WpEvently <= 4.3.6 - Authenticated (Contributor+) PHP Object Injection
high
The WpEvently plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.3.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable so...
- CVSS:
- 8.8
- Affected:
- up to 4.3.6
- Fixed in:
- 4.3.7
- Disclosed:
- Apr 8, 2025
CVE-2025-32145 on NVD →
WpEvently <= 4.2.9 - Authenticated (Contributor+) Local File Inclusion
high
The WpEvently plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.2.9. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This...
- CVSS:
- 8.8
- Affected:
- up to 4.2.9
- Fixed in:
- 4.3.0
- Disclosed:
- Mar 27, 2025
CVE-2025-30895 on NVD →
WpEvently <= 4.2.9 - Missing Authorization
medium
The Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.9. This makes it possible for unauthenticated attackers to perform an unauthoriz...
- CVSS:
- 5.3
- Affected:
- up to 4.2.9
- Fixed in:
- 4.3.0
- Disclosed:
- Mar 27, 2025
CVE-2025-30887 on NVD →
Event Booking Manager for WooCommerce [mage-eventpress] < 4.3.0
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in magepeopleteam WpEvently allows PHP Local File Inclusion. This issue affects WpEvently: from n/a through 4.2.9.
- Affected:
- up to 4.3.0
- Fixed in:
- 4.3.0
- Disclosed:
- Mar 27, 2025
CVE-2025-30895 on NVD →
Event Booking Manager for WooCommerce [mage-eventpress] < 4.3.0
unknown
[en] Missing Authorization vulnerability in magepeopleteam WpEvently allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpEvently: from n/a through 4.2.9.
- Affected:
- up to 4.3.0
- Fixed in:
- 4.3.0
- Disclosed:
- Mar 27, 2025
CVE-2025-30887 on NVD →
Event Booking Manager for WooCommerce [mage-eventpress] < 4.2.6
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagePeople Team Event Manager for WooCommerce allows Stored XSS.This issue affects Event Manager for WooCommerce: from n/a through 4.2.5.
- Affected:
- up to 4.2.6
- Fixed in:
- 4.2.6
- Disclosed:
- Oct 24, 2024
CVE-2024-49703 on NVD →
Event Manager for WooCommerce <= 4.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Event Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scr...
- CVSS:
- 6.4
- Affected:
- up to 4.2.5
- Fixed in:
- 4.2.6
- Disclosed:
- Oct 21, 2024
CVE-2024-49703 on NVD →
Event Booking Manager for WooCommerce [mage-eventpress] < 4.2.2
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MagePeople Team Event Manager for WooCommerce allows PHP Local File Inclusion.This issue affects Event Manager for WooCommerce: from n/a through 4.2.1.
- Affected:
- up to 4.2.2
- Fixed in:
- 4.2.2
- Disclosed:
- Aug 13, 2024
CVE-2024-43138 on NVD →
Event Manager for WooCommerce <= 4.2.1 - Authenticated (Contributor+) Local File Inclusion
critical
The Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.1 via the 'mep_event_template' parameter. This makes it possible for authenticated attackers, with contributor-level access and...
- CVSS:
- 9.9
- Affected:
- up to 4.2.1
- Fixed in:
- 4.2.2
- Disclosed:
- Aug 7, 2024
CVE-2024-43138 on NVD →
Appsero <= 2.0.0 - Missing Authorization via handle_optin_optout
medium
The Appsero analytics tool used in several plugins is vulnerable to unauthorized modification of data due to a missing capability check on the handle_optin_optout function in versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to opt-in or opt-out of tracking. This was patched in...
- CVSS:
- 4.3
- Affected:
- up to 4.1.2
- Fixed in:
- 4.1.3
- Disclosed:
- Apr 11, 2024
CVE-2024-32110 on NVD →
Event Booking Manager for WooCommerce [mage-eventpress] < 4.1.2
unknown
[en] Deserialization of Untrusted Data vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin.This issue affects Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin: from n/a through 4.1.1.
- Affected:
- up to 4.1.2
- Fixed in:
- 4.1.2
- Disclosed:
- Feb 12, 2024
CVE-2024-24796 on NVD →
Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently <= 4.1.1 - Authenticated (Contributor+) PHP Object Injection in mep_event_meta_save
high
The Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.1 via deserialization of untrusted input in the mep_event_meta_save function. This makes it possible for authenticated attackers, with contributor...
- CVSS:
- 8.8
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.2
- Disclosed:
- Jan 31, 2024
CVE-2024-24796 on NVD →
Event Booking Manager for WooCommerce [mage-eventpress] < 3.9.6
unknown
[en] Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.9.5 versions.
- Affected:
- up to 3.9.6
- Fixed in:
- 3.9.6
- Disclosed:
- Jul 18, 2023
CVE-2023-36383 on NVD →
Event Booking Manager for WooCommerce [mage-eventpress] < 3.7.8
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.7.7 versions.
- Affected:
- up to 3.7.8
- Fixed in:
- 3.7.8
- Disclosed:
- May 25, 2023
CVE-2022-47164 on NVD →
Event Booking Manager for WooCommerce [mage-eventpress] < 3.8.7
unknown
[en] Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce <= 3.8.6. versions.
- Affected:
- up to 3.8.7
- Fixed in:
- 3.8.7
- Disclosed:
- Mar 23, 2023
CVE-2023-28422 on NVD →
Event Manager for WooCommerce <= 3.8.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'mep_get_option' function
medium
The Event Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mep_get_option' function in versions up to, and including, 3.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level access, an...
- CVSS:
- 4.4
- Affected:
- up to 3.8.6
- Fixed in:
- 3.8.7
- Disclosed:
- Mar 20, 2023
CVE-2023-28422 on NVD →
Event Manager for WooCommerce <= 3.7.7 - Cross-Site Request Forgery leading to Uninstall Form Submission
medium
The Event Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.7. This is due to missing or incorrect nonce validation on the 'uninstall_reason_submission' function. This makes it possible for unauthenticated attackers to submit plugin uninstall...
- CVSS:
- 4.3
- Affected:
- up to 3.7.7
- Fixed in:
- 3.7.8
- Disclosed:
- Mar 16, 2023
CVE-2022-47164 on NVD →
Event Booking Manager for WooCommerce [mage-eventpress] < 3.8.0
unknown
[en] The Event Manager and Tickets Selling Plugin for WooCommerce WordPress plugin before 3.8.0 does not validate and escape some of its post meta before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.0
- Disclosed:
- Feb 6, 2023
CVE-2023-0144 on NVD →
Event Manager and Tickets Selling Plugin for WooCommerce <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Event Manager and Tickets Selling Plugin for WooCommerce is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 3.7.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with co...
- CVSS:
- 6.4
- Affected:
- up to 3.7.9
- Fixed in:
- 3.8.0
- Disclosed:
- Jan 10, 2023
CVE-2023-0144 on NVD →
Event Booking Manager for WooCommerce [mage-eventpress] < 3.5.8
unknown
[en] The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which could allow users with a role as low as contributor to perform SQL Injection attacks
- Affected:
- up to 3.5.8
- Fixed in:
- 3.5.8
- Disclosed:
- Mar 14, 2022
CVE-2022-0478 on NVD →
Event Manager and Tickets Selling for WooCommerce < 3.5.8 - SQL Injection
high
The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which could allow users with a role as low as contributor to perform SQL Injection attacks
- CVSS:
- 8.8
- Affected:
- up to 3.5.8
- Fixed in:
- 3.5.8
- Disclosed:
- Feb 21, 2022
CVE-2022-0478 on NVD →
Event Manager and Tickets Selling Plugin for WooCommerce < 3.5.3 - Arbitrary Settings Change
medium
The Event Manager and Tickets Selling Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary settings reset via the mep_wl_ajax_license_activate and mep_wl_ajax_license_deactivate functions in versions before 3.5.3. This is due to a missing capabilities check on these functions. This makes it possible f...
- CVSS:
- 6.5
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.3
- Disclosed:
- Nov 3, 2021
Event Manager and Tickets Selling Plugin for WooCommerce < 3.5.3 - Missing Authorization
medium
The Event Manager and Tickets Selling Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary template import in versions before 3.5.3 via the mep_import_ajax_template function. This is due to a missing capability check on this function. This makes it possible for unauthenticated attackers to arbitrarily...
- CVSS:
- 5.3
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.3
- Disclosed:
- Nov 3, 2021
Event Booking Manager for WooCommerce [mage-eventpress] < 3.5.3
unknown
Unauthenticated Arbitrary Options Reset vulnerability discovered by WPScanTeam in WordPress Event Manager for WooCommerce plugin (versions <= 3.5.1).
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.3
- Disclosed:
- Nov 3, 2021
Event Booking Manager for WooCommerce [mage-eventpress] < 3.5.3
unknown
Unauthenticated Arbitrary Elementor Template Import vulnerability discovered by WPScanTeam in WordPress Event Manager for WooCommerce plugin (versions <= 3.5.1).
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.3
- Disclosed:
- Nov 3, 2021
Event Booking Manager for WooCommerce [mage-eventpress] < 3.5.3
unknown
The Event Manager and Tickets Selling Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary settings reset via the mep_wl_ajax_license_activate and mep_wl_ajax_license_deactivate functions in versions before 3.5.3. This is due to a missing capabilities check on these functions. This makes it possible f...
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.3
- Disclosed:
- Nov 3, 2021
Event Booking Manager for WooCommerce [mage-eventpress] < 3.5.3
unknown
The Event Manager and Tickets Selling Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary template import in versions before 3.5.3 via the mep_import_ajax_template function. This is due to a missing capability check on this function. This makes it possible for unauthenticated attackers to arbitrarily...
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.3
- Disclosed:
- Nov 3, 2021
Event Booking Manager for WooCommerce [mage-eventpress] < 4.4.3
unknown
- Affected:
- up to 4.4.3
- Fixed in:
- 4.4.3
CVE-2025-5568 on NVD →
Event Booking Manager for WooCommerce [mage-eventpress] < 4.1.3
unknown
- Affected:
- up to 4.1.3
- Fixed in:
- 4.1.3
CVE-2024-32110 on NVD →
Event Booking Manager for WooCommerce [mage-eventpress] < 4.1.2
unknown
Update the WordPress Event Manager for WooCommerce plugin to the latest available version (at least 4.1.2).
Ngô Thiên An (ancorn_ from VNPT-VCI) discovered and reported this PHP Object Injection vulnerability in WordPress Event Manager for WooCommerce Plugin. This could allow a malicious actor to execute code injection...
- Affected:
- up to 4.1.2
- Fixed in:
- 4.1.2
Event Booking Manager for WooCommerce [mage-eventpress] < 3.5.3
unknown
The plugin has two AJAX actions, mep_wl_ajax_license_activate and mep_wl_ajax_license_deactivate, which are available to both unauthenticated and authenticated users, and are lacking any authorisation, CSRF as well as checks to ensure that the options to be updated belong to the plugin. As a result, unauthenticated use...
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.3
Event Booking Manager for WooCommerce [mage-eventpress] < 3.5.3
unknown
The mep_import_ajax_template AJAX action of the plugin, available to both unauthenticated and authenticated users, is lacking any authorisation and CSRF checks. As a result, unauthenticated user can import arbitrary Elementor template to the blog
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.3