plugin

Wp Event Manager Vulnerabilities

21 known security issues reported for the Wp Event Manager WordPress plugin. Most recent disclosed Jul 15, 2025.

1 critical 2 high 8 medium

Running Wp Event Manager on your site? Check whether your installed version is affected.

Scan your site free

WP Event Manager <= 3.1.50 - Unauthenticated Stored Cross-Site Scripting via 'organizer_name'

high

The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘organizer_name' parameter in all versions up to, and including, 3.1.50 due to insufficient input sanitization and output escaping. This makes it possible for un...

CVSS:
7.2
Affected:
up to 3.1.50
Fixed in:
3.1.51
Disclosed:
Jul 15, 2025

CVE-2025-2800 on NVD →

WP Event Manager <= 3.1.49 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tag-name’ parameter in all versions up to, and including, 3.1.49 due to insufficient input sanitization and output escaping. This makes it possible for authenti...

CVSS:
4.4
Affected:
up to 3.1.49
Fixed in:
3.1.50
Disclosed:
Jun 10, 2025

CVE-2025-2799 on NVD →

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce [wp-event-manager] <= 3.1.49 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Event Manager WP Event Manager allows PHP Local File Inclusion. This issue affects WP Event Manager: from n/a through 3.1.49.

Affected:
up to 3.1.49
Fix:
No patched version reported
Disclosed:
Jun 9, 2025

CVE-2025-48125 on NVD →

WP Event Manager <= 3.1.51 - Unauthenticated Local File Inclusion

critical

The WP Event Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.1.51. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access co...

CVSS:
9.8
Affected:
up to 3.1.51
Fixed in:
3.2.0
Disclosed:
May 21, 2025

CVE-2025-48125 on NVD →

WP Event Manager <= 3.2.0 - Missing Authorization

medium

The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.2.0. This makes it possible for authenticated attackers, with Subscriber-level access and...

CVSS:
4.3
Affected:
up to 3.2.0
Fixed in:
3.2.1
Disclosed:
Apr 4, 2025

CVE-2025-32225 on NVD →

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce [wp-event-manager] <= 3.1.48 (unfixed)

unknown

[en] Missing Authorization vulnerability in WP Event Manager WP Event Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Event Manager: from n/a through 3.1.47.

Affected:
up to 3.1.48
Fix:
No patched version reported
Disclosed:
Apr 4, 2025

CVE-2025-32225 on NVD →

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce [wp-event-manager] < 3.1.44

unknown

[en] The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events' shortcode in all versions up to, and including, 3.1.43 due to insufficient input sanitization and output escaping on user supplied attribu...

Affected:
up to 3.1.44
Fixed in:
3.1.44
Disclosed:
Jul 16, 2024

CVE-2024-2691 on NVD →

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce <= 3.1.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'events' Shortcode

medium

The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events' shortcode in all versions up to, and including, 3.1.43 due to insufficient input sanitization and output escaping on user supplied attributes....

CVSS:
6.4
Affected:
up to 3.1.43
Fixed in:
3.1.44
Disclosed:
Jul 15, 2024

CVE-2024-2691 on NVD →

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce [wp-event-manager] < 3.1.42

unknown

[en] The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the plugin parameter in all versions up to, and including, 3.1.41 due to insufficient input sanitization and output escaping. This makes it possible for unau...

Affected:
up to 3.1.42
Fixed in:
3.1.42
Disclosed:
Mar 13, 2024

CVE-2024-0976 on NVD →

WP Event Manager <= 3.1.41 - Reflected Cross-Site Scripting via plugin

medium

The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the plugin parameter in all versions up to, and including, 3.1.41 due to insufficient input sanitization and output escaping. This makes it possible for unauthent...

CVSS:
6.1
Affected:
up to 3.1.41
Fixed in:
3.1.42
Disclosed:
Feb 23, 2024

CVE-2024-0976 on NVD →

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce [wp-event-manager] < 3.1.42

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Event Manager WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce allows Stored XSS.This issue affects WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommer...

Affected:
up to 3.1.42
Fixed in:
3.1.42
Disclosed:
Dec 15, 2023

CVE-2023-49181 on NVD →

WP Event Manager <= 3.1.41 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The WP Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.41 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages tha...

CVSS:
5.5
Affected:
up to 3.1.41
Fixed in:
3.1.42
Disclosed:
Nov 29, 2023

CVE-2023-49181 on NVD →

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce [wp-event-manager] < 3.1.43

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Event Manager WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin <= 3.1.39 versions.

Affected:
up to 3.1.43
Fixed in:
3.1.43
Disclosed:
Nov 13, 2023

CVE-2023-47697 on NVD →

WP Event Manager <= 3.1.42 - Cross-Site Scripting

high

The WP Event Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.1.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...

CVSS:
7.2
Affected:
up to 3.1.42
Fixed in:
3.1.43
Disclosed:
Nov 9, 2023

CVE-2023-47697 on NVD →

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce [wp-event-manager] < 3.1.38

unknown

[en] The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.1.37.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...

Affected:
up to 3.1.38
Fixed in:
3.1.38
Disclosed:
Sep 27, 2023

CVE-2023-4423 on NVD →

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce <= 3.1.37.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.1.37.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac...

CVSS:
4.4
Affected:
up to 3.1.37.1
Fixed in:
3.1.38
Disclosed:
Sep 20, 2023

CVE-2023-4423 on NVD →

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce [wp-event-manager] < 3.1.28

unknown

[en] The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in an attribute on the event dashboard, leading to a Reflected Cross-Site Scripting

Affected:
up to 3.1.28
Fixed in:
3.1.28
Disclosed:
Jul 11, 2022

CVE-2022-1474 on NVD →

WP Event Manager – Easily Build your Calendar of Events! <= 3.1.27 - Stored Cross Site Scripting

medium

The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in an attribute on the event dashboard, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 3.1.28
Fixed in:
3.1.28
Disclosed:
Jun 20, 2022

CVE-2022-1474 on NVD →

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce [wp-event-manager] < 3.1.23

unknown

[en] The WP Event Manager WordPress plugin before 3.1.23 does not escape some of its Field Editor settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Affected:
up to 3.1.23
Fixed in:
3.1.23
Disclosed:
Mar 7, 2022

CVE-2021-24810 on NVD →

WP Event Manager <= 3.1.22 - Admin+ Stored Cross-Site Scripting

medium

The WP Event Manager WordPress plugin before 3.1.23 does not escape some of its Field Editor settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVSS:
4.8
Affected:
up to 3.1.22
Fixed in:
3.1.23
Disclosed:
Feb 14, 2022

CVE-2021-24810 on NVD →

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce [wp-event-manager] < 3.1.51

unknown
Affected:
up to 3.1.51
Fixed in:
3.1.51

CVE-2025-2800 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database