Multiple Plugins by emarket-design <= Multiple Versions - Unauthenticated Limited Remote Code Execution
high
Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code Execution in various versions via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible fo...
- CVSS:
- 8.1
- Affected:
- up to 4.2.1
- Fixed in:
- 4.2.2
- Disclosed:
- Aug 5, 2025
CVE-2025-8420 on NVD →
Event RSVP and Simple Event Management Plugin <= 4.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Event RSVP and Simple Event Management Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'emd_mb_meta' shortcode in all versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...
- CVSS:
- 6.4
- Affected:
- up to 4.1.0
- Fixed in:
- 4.2.0
- Disclosed:
- Jun 25, 2025
CVE-2025-5540 on NVD →
Event Management, Events Calendar, RSVP Event Tickets Plugin <= 3.8.4 - Cross-Site Scripting
medium
The Event Management, Events Calendar, RSVP Event Tickets Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 3.8.4 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in p...
- CVSS:
- 5.4
- Affected:
- up to 3.8.4
- Fixed in:
- 3.8.5
- Disclosed:
- May 18, 2022
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database