Extension WordPress
Vulnérabilités Eventer – WordPress Event & Booking Manager Plugin
Cette page rassemble les failles publiées pour Eventer – WordPress Event & Booking Manager Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Eventer – WordPress Event & Booking Manager Plugin
12 fiches
Eventer <= 4.4.2 – Unauthenticated SQL Injection via 'code' Parameter
The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
*-4.4.2
Non indiqué
07/07/2026
Eventer <= 4.4.2 – Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation
The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of the password reset key in the `eventer_verification_code` user meta field…
*-4.4.2
Non indiqué
07/07/2026
Eventer <= 3.11.2.1 – Unauthenticated Arbitrary Shortcode Execution
The The Eventer – WordPress Event & Booking Manager Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.11.2.1. This is due to the software allowing users to execute an…
*-3.11.2.1
3.11.2.2
04/08/2025
Eventer <= 3.9.6 – Missing Authorization
The Eventer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.9.6. This makes it possible for authenticated attackers, with Subscriber-level access and…
*-3.9.6
Non indiqué
16/05/2025
Eventer <= 3.9.6 – Unauthenticated SQL Injection
The Eventer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-3.9.6
Non indiqué
16/05/2025
Eventer – WordPress Event & Booking Manager Plugin <= 3.9.9.2 – Authenticated (Subscriber+) SQL Injection via reg_id
The Eventer – WordPress Event & Booking Manager Plugin plugin for WordPress is vulnerable to SQL Injection via the reg_id parameter in all versions up to, and including, 3.9.9.2 due to insufficient escaping on the user supplied parameter…
*-3.9.9.2
3.9.9.3
06/03/2025
Eventer <= 3.9.8 – Reflected Cross-Site Scripting
The Eventer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.9.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-3.9.8
3.9.9
14/02/2025
Eventer <= 3.9.9.5 – Missing Authorization to Unauthenticated Event Ticket Download
The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_pdf_download_request' function in all versions up to, and including, 3.9.9.5. This makes it possible for unauthenticated attackers to…
*-3.9.9.5
3.9.9.5.1
03/02/2025
Eventer <= 3.9.9.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Eventer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.9.9.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
*-3.9.9.4
3.9.9.5
03/02/2025
Eventer <= 3.9.9 – Missing Authorization to Authenticated (Subscriber+) Bookings Export
The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'eventer_export_bookings_csv' function in all versions up to, and including, 3.9.9. This makes it possible for authenticated attackers with…
*-3.9.9
3.9.9.1
03/02/2025
Eventer <= 3.9.8 – Unauthenticated SQL Injection via eventer_get_attendees
The Eventer plugin for WordPress is vulnerable to SQL Injection via the 'event' parameter in the 'eventer_get_attendees' function in all versions up to, and including, 3.9.8 due to insufficient escaping on the user supplied parameter and lack of…
*-3.9.8
3.9.9
27/01/2025
Eventer <= 3.9.7 – Authenticated (Subscriber+) Arbitrary File Read
The Eventer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.9.7 via the eventer_woo_download_tickets() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents…
*-3.9.7
3.9.8
16/01/2025
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.