CVE-2025-2799
- EPSS 0.04%
- Veröffentlicht 16.07.2025 05:23:51
- Zuletzt bearbeitet 16.07.2025 19:57:17
The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tag-name’ parameter in all versions up to, and including, 3.1.49 due to insufficient input...
CVE-2025-2800
- EPSS 0.13%
- Veröffentlicht 16.07.2025 05:23:50
- Zuletzt bearbeitet 16.07.2025 19:56:53
The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘organizer_name' parameter in all versions up to, and including, 3.1.50 due to insufficient...
CVE-2024-2691
- EPSS 0.15%
- Veröffentlicht 16.07.2024 09:15:02
- Zuletzt bearbeitet 21.11.2024 09:10:18
The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events' shortcode in all versions up to, and including, 3.1.43 due to insufficien...
CVE-2024-0976
- EPSS 1.49%
- Veröffentlicht 13.03.2024 16:15:15
- Zuletzt bearbeitet 07.03.2025 19:37:57
The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the plugin parameter in all versions up to, and including, 3.1.41 due to insufficient input ...
CVE-2023-52118
- EPSS 0.08%
- Veröffentlicht 01.02.2024 11:15:12
- Zuletzt bearbeitet 21.11.2024 08:39:12
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Event Manager WP User Profile Avatar allows Stored XSS.This issue affects WP User Profile Avatar: from n/a through 1.0.
CVE-2023-49181
- EPSS 0.12%
- Veröffentlicht 15.12.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 08:32:59
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Event Manager WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce allows Stored XSS.This issue affects WP Event Mana...
CVE-2023-47697
- EPSS 0.1%
- Veröffentlicht 13.11.2023 23:15:08
- Zuletzt bearbeitet 21.11.2024 08:30:41
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Event Manager WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin <= 3.1.39 versions.
CVE-2023-4423
- EPSS 0.32%
- Veröffentlicht 27.09.2023 15:19:40
- Zuletzt bearbeitet 21.11.2024 08:35:07
The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.1.37.1 due to insufficient input sanitizati...
CVE-2022-1474
- EPSS 0.22%
- Veröffentlicht 11.07.2022 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:40:47
The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in an attribute on the event dashboard, leading to a Reflected Cross-Site Scripting
CVE-2021-24810
- EPSS 0.21%
- Veröffentlicht 07.03.2022 09:15:07
- Zuletzt bearbeitet 21.11.2024 05:53:48
The WP Event Manager WordPress plugin before 3.1.23 does not escape some of its Field Editor settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed