CVE-2025-14945
- EPSS 0.22%
- Veröffentlicht 05.09.2026 05:30:55
- Zuletzt bearbeitet 08.09.2026 13:12:58
The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event attribute values in all versions up to, and including, 7.3.3. This is due to insufficient input sanitization when ...
CVE-2026-14280
- EPSS 0.71%
- Veröffentlicht 25.08.2026 03:27:07
- Zuletzt bearbeitet 26.08.2026 16:19:05
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.3.7.4 via the em_options_save function. This makes it possible for authenticated attackers,...
CVE-2026-17089
- EPSS 0.28%
- Veröffentlicht 25.08.2026 03:27:06
- Zuletzt bearbeitet 26.08.2026 16:19:05
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'header_format' parameter in all versions up to, and including, 7.4.0.1 due to insufficient input sanitization an...
CVE-2026-10627
- EPSS 0.33%
- Veröffentlicht 25.08.2026 02:26:48
- Zuletzt bearbeitet 27.08.2026 17:17:06
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.4.0. This is due to the plugin not properly verifying that a user is authorized to perform ...
CVE-2026-15023
- EPSS 0.43%
- Veröffentlicht 25.08.2026 01:26:44
- Zuletzt bearbeitet 26.08.2026 16:19:05
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to generic SQL Injection via Stored 'meta_key' via Event/Location Duplicate Action in all versions up to, and including, 7.4.0 due to insufficient escaping...
CVE-2025-12976
- EPSS 0.42%
- Veröffentlicht 18.12.2025 07:20:45
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list_grouped' shortcode in all versions up to, and including, 7.2.2.1 due to insufficient input san...
CVE-2025-12407
- EPSS 0.12%
- Veröffentlicht 12.12.2025 11:15:51
- Zuletzt bearbeitet 07.10.2026 20:10:01
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.2.2. This is due to missing or incorrect nonce validation on the 'location_delete' ...
CVE-2025-12408
- EPSS 0.32%
- Veröffentlicht 12.12.2025 11:15:50
- Zuletzt bearbeitet 07.10.2026 20:10:01
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 7.2.2.2 via the 'get_location' action due to insufficient restrictions on which locations can...
CVE-2025-6975
- EPSS 0.25%
- Veröffentlicht 09.07.2025 22:22:47
- Zuletzt bearbeitet 11.07.2025 17:27:10
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘calendar_header’ parameter in all versions up to, and including, 7.0.3 due to insufficient input sanitization an...
CVE-2025-6976
- EPSS 0.23%
- Veröffentlicht 09.07.2025 22:22:47
- Zuletzt bearbeitet 11.07.2025 17:26:52
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output e...