Extension WordPress

Vulnérabilités EventPrime – Events Calendar, Bookings and Tickets

Cette page rassemble les failles publiées pour EventPrime – Events Calendar, Bookings and Tickets, leurs plages de versions affectées et les correctifs signalés dans la base locale.

45Vulnérabilités
0Critiques
45Avec correctif
8,1CVSS maximal

Historique de sécurité

CVE et vulnérabilités de EventPrime – Events Calendar, Bookings and Tickets

45 fiches

CVE-2026-13441 Élevée · 7,2
EventPrime – Events Calendar, Bookings and Tickets

EventPrime <= 4.3.4.2 – Unauthenticated Stored Cross-Site Scripting via 'new_event_type_background_color' Parameter

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_event_type_background_color' parameter in all versions up to, and including, 4.3.4.2 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-4.3.4.2

Correctif

4.3.4.3

Publication

08/07/2026

CVE-2026-56053 Élevée · 7,5
EventPrime – Events Calendar, Bookings and Tickets

EventPrime – Events Calendar, Bookings and Tickets <= 4.3.4.1 – Authenticated (Subscriber+) PHP Object Injection

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.3.4.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level…

Versions affectées

*-4.3.4.1

Correctif

4.3.4.2

Publication

25/06/2026

CVE-2026-42687 Élevée · 8,1
EventPrime – Events Calendar, Bookings and Tickets

EventPrime – Events Calendar, Bookings and Tickets <= 4.3.2.1 – Unauthenticated PHP Object Injection

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.3.2.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject…

Versions affectées

*-4.3.2.1

Correctif

4.3.2.2

Publication

25/05/2026

CVE-2026-42686 Moyenne · 6,4
EventPrime – Events Calendar, Bookings and Tickets

EventPrime – Events Calendar, Bookings and Tickets <= 4.3.2.1 – Authenticated (Subscriber+) Stored Cross-Site Scripting

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-4.3.2.1

Correctif

4.3.2.2

Publication

24/05/2026

CVE-2026-42669 Moyenne · 5,3
EventPrime – Events Calendar, Bookings and Tickets

EventPrime – Events Calendar, Bookings and Tickets <= 4.3.2.0 – Missing Authorization

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.3.2.0. This makes it possible for unauthenticated…

Versions affectées

*-4.3.2.0

Correctif

4.3.2.1

Publication

12/05/2026

CVE-2026-39518 Moyenne · 4,3
EventPrime – Events Calendar, Bookings and Tickets

EventPrime – Events Calendar, Bookings and Tickets <= 4.3.0.0 – Authenticated (Subscriber+) Insecure Direct Object Reference

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.0.0 due to missing validation on a user controlled key. This makes it…

Versions affectées

*-4.3.0.0

Correctif

4.3.0.1

Publication

20/04/2026

CVE-2026-25312 Moyenne · 5,3
EventPrime – Events Calendar, Bookings and Tickets

EventPrime – Events Calendar, Bookings and Tickets <= 4.2.8.3 – Missing Authorization

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.8.3. This makes it possible for…

Versions affectées

*-4.2.8.3

Correctif

4.2.8.4

Publication

18/03/2026

CVE-2026-24378 Élevée · 8,1
EventPrime – Events Calendar, Bookings and Tickets

EventPrime – Events Calendar, Bookings and Tickets <= 4.2.8.0 – Unauthenticated PHP Object Injection

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.8.0 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject…

Versions affectées

*-4.2.8.0

Correctif

4.2.8.1

Publication

17/03/2026

CVE-2025-69358 Moyenne · 5,3
EventPrime – Events Calendar, Bookings and Tickets

EventPrime – Events Calendar, Bookings and Tickets <= 4.2.6.0 – Missing Authorization

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.6.0. This makes it possible for…

Versions affectées

*-4.2.6.0

Correctif

4.2.7.0

Publication

10/03/2026

CVE-2026-25389 Moyenne · 5,3
EventPrime – Events Calendar, Bookings and Tickets

EventPrime <= 4.2.8.3 – Unauthenticated Information Exposure

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.8.3. This makes it possible for unauthenticated attackers to extract sensitive user or configuration…

Versions affectées

*-4.2.8.3

Correctif

4.2.8.4

Publication

20/02/2026

CVE-2026-1655 Moyenne · 4,3
EventPrime – Events Calendar, Bookings and Tickets

EventPrime <= 4.2.8.4 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Event Modification via 'event_id' Parameter

The EventPrime plugin for WordPress is vulnerable to unauthorized post modification due to missing authorization checks in all versions up to, and including, 4.2.8.4. This is due to the save_frontend_event_submission function accepting a user-controlled event_id parameter and updating…

Versions affectées

*-4.2.8.4

Correctif

4.2.8.5

Publication

17/02/2026

CVE-2026-1657 Moyenne · 5,3
EventPrime – Events Calendar, Bookings and Tickets

EventPrime <= 4.2.8.4 – Missing Authorization to Unauthenticated Image Upload via 'ep_upload_file_media' AJAX Endpoint

The EventPrime plugin for WordPress is vulnerable to unauthorized image file upload in all versions up to, and including, 4.2.8.4. This is due to the plugin registering the upload_file_media AJAX action as publicly accessible (nopriv-enabled) without implementing any…

Versions affectées

*-4.2.8.4

Correctif

4.2.8.5

Publication

16/02/2026

CVE-2025-14507 Moyenne · 5,3
EventPrime – Events Calendar, Bookings and Tickets

EventPrime – Events Calendar, Bookings and Tickets <= 4.2.7.0 – Unauthenticated Sensitive Information Exposure via REST API

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.7.0 via the REST API. This makes it possible for unauthenticated attackers to extract…

Versions affectées

*-4.2.7.0

Correctif

4.2.8.0

Publication

12/01/2026

CVE-2025-12498 Moyenne · 4,3
EventPrime – Events Calendar, Bookings and Tickets

EventPrime – Events Calendar, Bookings and Tickets <= 4.2.0.0 – Missing Authorization to Authenticated (Subscriber+) Booking Note Creation

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized booking note creation due to a missing capability check on the 'booking_add_notes' function in all versions up to, and including, 4.2.0.0. This makes…

Versions affectées

*-4.2.0.0

Correctif

4.2.0.1

Publication

07/11/2025

CVE-2025-63007 Moyenne · 4,3
EventPrime – Events Calendar, Bookings and Tickets

EventPrime <= 4.2.4.1 – Authenticated (Subscriber+) Information Exposure

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…

Versions affectées

*-4.2.4.1

Correctif

4.2.5.0

Publication

06/11/2025

CVE-2024-13526 Moyenne · 4,3
EventPrime – Events Calendar, Bookings and Tickets

EventPrime – Events Calendar, Bookings and Tickets <= 4.0.7.3 – Missing Authorization to Authenticated (Subscriber+) Event Attendees Export

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the export_submittion_attendees function in all versions up to, and including, 4.0.7.3. This makes…

Versions affectées

*-4.0.7.3

Correctif

4.0.7.4

Publication

06/03/2025

CVE-2024-12024 Élevée · 7,2
EventPrime – Events Calendar, Bookings and Tickets

EventPrime – Events Calendar, Bookings and Tickets <= 4.0.7.3 – Unauthenticated Stored Cross-Site Scripting via Ticket Category and Ticket Type Name

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the em_ticket_category_data and em_ticket_individual_data parameters in all versions up to, and including, 4.0.7.3 due to insufficient input sanitization and output…

Versions affectées

*-4.0.7.3

Correctif

4.0.7.4

Publication

16/12/2024

CVE-2024-4665 Moyenne · 4,3
EventPrime – Events Calendar, Bookings and Tickets

EventPrime – Events Calendar, Bookings and Tickets <= 3.5.0 – Insecure Direct Object Reference to (Subscriber+) Arbitrary Booking Update

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.9 due to missing validation on a user controlled key. This makes it…

Versions affectées

*-3.4.9

Correctif

3.5.0

Publication

29/10/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités