Extension WordPress
Vulnérabilités Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar
Cette page rassemble les failles publiées pour Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar
24 fiches
Event Booking Manager for WooCommerce <= 5.3.3 – Missing Authorization
The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.3.3. This makes it possible for unauthenticated attackers…
*-5.3.3
5.3.4
26/05/2026
Event Booking Manager for WooCommerce <= 5.1.4 – Reflected Cross-Site Scripting
The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-5.1.4
5.1.5
20/03/2026
WpEvently <= 5.1.1 – Unauthenticated PHP Object Injection
The WpEvently plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.1.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP…
*-5.1.1
5.1.2
18/02/2026
WpEvently < 5.1.9 – Unauthenticated Information Exposure
The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 5.1.9 (exclusive). This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
[*, 5.1.9)
5.1.9
14/02/2026
WpEvently <= 5.0.8 – Authenticated (Contributor+) PHP Object Injection
The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.8 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access…
*-5.0.8
5.0.9
25/12/2025
WpEvently <= 5.1.1 – Cross-Site Request Forgery
The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on a function. This makes it…
*-5.1.1
5.1.2
06/12/2025
WpEvently <= 5.0.4 – Missing Authorization
The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.0.4. This makes it possible for unauthenticated attackers…
*-5.0.4
5.0.5
04/12/2025
WpEvently <= 5.0.4 – Missing Authorization
The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.0.4. This makes it possible for unauthenticated attackers…
*-5.0.4
5.0.5
30/11/2025
WpEvently <= 4.4.8 – Authenticated (Contributor+) PHP Object Injection
The WpEvently plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.4.8 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a…
*-4.4.8
4.4.9
27/08/2025
WpEvently <= 4.4.6 – Missing Authorization
The Event Booking Manager for WooCommerce – WpEvently plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.4.6. This makes it possible for…
*-4.4.6
4.4.7
30/07/2025
WpEvently <= 4.4.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-4.4.2
4.4.3
06/06/2025
WpEvently <= 4.3.6 – Authenticated (Contributor+) PHP Object Injection
The WpEvently plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.3.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a…
*-4.3.6
4.3.7
08/04/2025
WpEvently <= 4.2.9 – Missing Authorization
The Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including,…
*-4.2.9
4.3.0
27/03/2025
WpEvently <= 4.2.9 – Authenticated (Contributor+) Local File Inclusion
The WpEvently plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.2.9. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the…
*-4.2.9
4.3.0
27/03/2025
Event Manager for WooCommerce <= 4.2.5 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Event Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-4.2.5
4.2.6
21/10/2024
Event Manager for WooCommerce <= 4.2.1 – Authenticated (Contributor+) Local File Inclusion
The Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.1 via the 'mep_event_template' parameter. This makes it…
*-4.2.1
4.2.2
07/08/2024
Appsero <= 2.0.0 – Missing Authorization via handle_optin_optout
The Appsero analytics tool used in several plugins is vulnerable to unauthorized modification of data due to a missing capability check on the handle_optin_optout function in versions up to, and including, 2.0.0. This makes it possible for unauthenticated…
*-4.1.2
4.1.3
11/04/2024
Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently <= 4.1.1 – Authenticated (Contributor+) PHP Object Injection in mep_event_meta_save
The Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.1 via deserialization of untrusted input in the mep_event_meta_save function. This…
*-4.1.1
4.1.2
31/01/2024
Event Manager for WooCommerce <= 3.8.6 – Authenticated (Administrator+) Stored Cross-Site Scripting via 'mep_get_option' function
The Event Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mep_get_option' function in versions up to, and including, 3.8.6 due to insufficient input sanitization and output escaping. This makes it possible for…
*-3.8.6
3.8.7
20/03/2023
Event Manager for WooCommerce <= 3.7.7 – Cross-Site Request Forgery leading to Uninstall Form Submission
The Event Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.7. This is due to missing or incorrect nonce validation on the 'uninstall_reason_submission' function. This makes it possible…
*-3.7.7
3.7.8
16/03/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.