Extension WordPress

Vulnérabilités Events Manager – Calendar, Bookings, Tickets, and more!

Cette page rassemble les failles publiées pour Events Manager – Calendar, Bookings, Tickets, and more!, leurs plages de versions affectées et les correctifs signalés dans la base locale.

35Vulnérabilités
1Critiques
35Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Events Manager – Calendar, Bookings, Tickets, and more!

35 fiches

CVE-2026-57713 Élevée · 8,1
Events Manager – Calendar, Bookings, Tickets, and more!

Events Manager – Calendar, Bookings, Tickets, and more! <= 7.3.6 – Unauthenticated PHP Object Injection

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 7.3.6 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to…

Versions affectées

*-7.3.6

Correctif

7.3.7

Publication

08/07/2026

CVE-2025-12976 Moyenne · 6,4
Events Manager – Calendar, Bookings, Tickets, and more!

Events Manager <= 7.2.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'events_list_grouped' Shortcode

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list_grouped' shortcode in all versions up to, and including, 7.2.2.1 due to insufficient input sanitization and output…

Versions affectées

*-7.2.2.1

Correctif

7.2.3

Publication

17/12/2025

CVE-2025-12407 Moyenne · 4,3
Events Manager – Calendar, Bookings, Tickets, and more!

Events Manager – Calendar, Bookings, Tickets, and more! <= 7.2.2.2 – Cross-Site Request Forgery to Location Deletion

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.2.2. This is due to missing or incorrect nonce validation on the 'location_delete'…

Versions affectées

*-7.2.2.2

Correctif

7.2.2.3

Publication

11/12/2025

CVE-2025-12408 Moyenne · 5,3
Events Manager – Calendar, Bookings, Tickets, and more!

Events Manager <= 7.2.2.2 – Unauthenticated Information Exposure

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 7.2.2.2 via the 'get_location' action due to insufficient restrictions on which locations can be…

Versions affectées

*-7.2.2.2

Correctif

7.2.2.3

Publication

11/12/2025

CVE-2025-6976 Moyenne · 6,4
Events Manager – Calendar, Bookings, Tickets, and more!

Events Manager <= 7.0.3 – Authenticated(Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escaping…

Versions affectées

*-6.6.4.4, 7.0.1-7.0.3

Correctif

6.6.5, 7.0.4

Publication

09/07/2025

CVE-2025-6970 Élevée · 7,5
Events Manager – Calendar, Bookings, Tickets, and more!

Events Manager <= 7.0.3 – Unauthenticated SQL Injection via `orderby` Parameter

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied…

Versions affectées

*-6.6.4.4, 7.0.1-7.0.3

Correctif

6.6.5, 7.0.4

Publication

09/07/2025

CVE-2025-6975 Moyenne · 6,1
Events Manager – Calendar, Bookings, Tickets, and more!

Event Manager <= 7.0.3 – Reflected Cross-Site Scripting via `calendar_header` Parameter

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘calendar_header’ parameter in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escaping.…

Versions affectées

*-6.6.4.4, 7.0.1-7.0.3

Correctif

6.6.5, 7.0.4

Publication

09/07/2025

CVE-2025-1249 Moyenne · 5,3
Events Manager – Calendar, Bookings, Tickets, and more!

Events Manager – Calendar, Bookings, Tickets, and more! <= 6.6.4.1 – Missing Authorization

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.6.4.1. This makes it possible…

Versions affectées

*-6.6.4.1

Correctif

6.6.4.2

Publication

26/02/2025

CVE-2024-11260 Élevée · 7,5
Events Manager – Calendar, Bookings, Tickets, and more!

Events Manager – Calendar, Bookings, Tickets, and more! <= 6.6.3 – Unauthenticated SQL Injection via Event Status Parameter

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient escaping on the user supplied…

Versions affectées

*-6.6.3

Correctif

6.6.4

Publication

20/02/2025

CVE-2024-5889 Moyenne · 6,1
Events Manager – Calendar, Bookings, Tickets, and more!

Events Manager <= 6.4.8 – Reflected Cross-Site Scripting

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping.…

Versions affectées

*-6.4.8

Correctif

6.4.9

Publication

28/06/2024

CVE-2024-3492 Moyenne · 6,4
Events Manager – Calendar, Bookings, Tickets, and more!

Events Manager – Calendar, Bookings, Tickets, and more! <= 6.4.7.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via event, location, and event_category Shortcodes

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' shortcodes in all versions up to, and including, 6.4.7.3 due to insufficient input…

Versions affectées

*-6.4.7.3

Correctif

6.4.8

Publication

11/06/2024

CVE-2024-2111 Moyenne · 6,4
Events Manager – Calendar, Bookings, Tickets, and more!

Events Manager <= 6.4.7.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the physical location value in all versions up to, and including, 6.4.7.1 due to insufficient input sanitization and output…

Versions affectées

*-6.4.7.1

Correctif

6.4.7.2

Publication

27/03/2024

CVE-2024-0614 Moyenne · 4,4
Events Manager – Calendar, Bookings, Tickets, and more!

Events Manager <= 6.4.6.4 – Authenticated(Administator+) Stored Cross-Site Scripting via settings

The Events Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.4.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

Versions affectées

*-6.4.6.4

Correctif

6.4.7

Publication

28/02/2024

CVE-2023-48326 Moyenne · 6,1
Events Manager – Calendar, Bookings, Tickets, and more!

Events Manager <= 6.4.5 – Reflected Cross-Site Scripting

The Events Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions up to, and including, 6.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

*-6.4.5

Correctif

6.4.6

Publication

23/11/2023

Vulnérabilité Élevée · 7,1
Events Manager – Calendar, Bookings, Tickets, and more!

Events Manager < 5.9.7.2 & Events Manager Pro < 2.6.7.2 – Unauthenticated CSV Injection

The Events Manager Pro, versions up to 2.6.7.2, and Events Manager, versions up to 5.9.7.2, plugins for WordPress are vulnerable to CSV Injection. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result…

Versions affectées

[*, 5.9.7.2)

Correctif

5.9.7.2

Publication

06/02/2020

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités