Extension WordPress

Vulnérabilités Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

Cette page rassemble les failles publiées pour Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar, leurs plages de versions affectées et les correctifs signalés dans la base locale.

24Vulnérabilités
1Critiques
24Avec correctif
9,9CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

24 fiches

CVE-2026-45441 Moyenne · 5,3
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

Event Booking Manager for WooCommerce <= 5.3.3 – Missing Authorization

The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.3.3. This makes it possible for unauthenticated attackers…

Versions affectées

*-5.3.3

Correctif

5.3.4

Publication

26/05/2026

CVE-2026-25361 Moyenne · 6,1
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

Event Booking Manager for WooCommerce <= 5.1.4 – Reflected Cross-Site Scripting

The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

*-5.1.4

Correctif

5.1.5

Publication

20/03/2026

CVE-2026-23549 Élevée · 8,1
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

WpEvently <= 5.1.1 – Unauthenticated PHP Object Injection

The WpEvently plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.1.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP…

Versions affectées

*-5.1.1

Correctif

5.1.2

Publication

18/02/2026

CVE-2026-32354 Moyenne · 4,3
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

WpEvently < 5.1.9 – Unauthenticated Information Exposure

The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 5.1.9 (exclusive). This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

Versions affectées

[*, 5.1.9)

Correctif

5.1.9

Publication

14/02/2026

CVE-2026-24954 Élevée · 7,5
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

WpEvently <= 5.0.8 – Authenticated (Contributor+) PHP Object Injection

The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.8 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access…

Versions affectées

*-5.0.8

Correctif

5.0.9

Publication

25/12/2025

CVE-2026-24942 Moyenne · 4,3
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

WpEvently <= 5.1.1 – Cross-Site Request Forgery

The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on a function. This makes it…

Versions affectées

*-5.1.1

Correctif

5.1.2

Publication

06/12/2025

CVE-2025-66083 Moyenne · 5,3
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

WpEvently <= 5.0.4 – Missing Authorization

The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.0.4. This makes it possible for unauthenticated attackers…

Versions affectées

*-5.0.4

Correctif

5.0.5

Publication

04/12/2025

CVE-2025-66082 Moyenne · 5,3
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

WpEvently <= 5.0.4 – Missing Authorization

The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.0.4. This makes it possible for unauthenticated attackers…

Versions affectées

*-5.0.4

Correctif

5.0.5

Publication

30/11/2025

CVE-2025-54742 Élevée · 7,5
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

WpEvently <= 4.4.8 – Authenticated (Contributor+) PHP Object Injection

The WpEvently plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.4.8 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a…

Versions affectées

*-4.4.8

Correctif

4.4.9

Publication

27/08/2025

CVE-2025-54705 Moyenne · 4,3
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

WpEvently <= 4.4.6 – Missing Authorization

The Event Booking Manager for WooCommerce – WpEvently plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.4.6. This makes it possible for…

Versions affectées

*-4.4.6

Correctif

4.4.7

Publication

30/07/2025

CVE-2025-5568 Moyenne · 6,4
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

WpEvently <= 4.4.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-4.4.2

Correctif

4.4.3

Publication

06/06/2025

CVE-2025-32145 Élevée · 8,8
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

WpEvently <= 4.3.6 – Authenticated (Contributor+) PHP Object Injection

The WpEvently plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.3.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a…

Versions affectées

*-4.3.6

Correctif

4.3.7

Publication

08/04/2025

CVE-2025-30887 Moyenne · 5,3
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

WpEvently <= 4.2.9 – Missing Authorization

The Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including,…

Versions affectées

*-4.2.9

Correctif

4.3.0

Publication

27/03/2025

CVE-2025-30895 Élevée · 8,8
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

WpEvently <= 4.2.9 – Authenticated (Contributor+) Local File Inclusion

The WpEvently plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.2.9. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the…

Versions affectées

*-4.2.9

Correctif

4.3.0

Publication

27/03/2025

CVE-2024-49703 Moyenne · 6,4
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

Event Manager for WooCommerce <= 4.2.5 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Event Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-4.2.5

Correctif

4.2.6

Publication

21/10/2024

CVE-2024-43138 Critique · 9,9
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

Event Manager for WooCommerce <= 4.2.1 – Authenticated (Contributor+) Local File Inclusion

The Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.1 via the 'mep_event_template' parameter. This makes it…

Versions affectées

*-4.2.1

Correctif

4.2.2

Publication

07/08/2024

CVE-2024-32110 Moyenne · 4,3
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

Appsero <= 2.0.0 – Missing Authorization via handle_optin_optout

The Appsero analytics tool used in several plugins is vulnerable to unauthorized modification of data due to a missing capability check on the handle_optin_optout function in versions up to, and including, 2.0.0. This makes it possible for unauthenticated…

Versions affectées

*-4.1.2

Correctif

4.1.3

Publication

11/04/2024

CVE-2024-24796 Élevée · 8,8
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently <= 4.1.1 – Authenticated (Contributor+) PHP Object Injection in mep_event_meta_save

The Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.1 via deserialization of untrusted input in the mep_event_meta_save function. This…

Versions affectées

*-4.1.1

Correctif

4.1.2

Publication

31/01/2024

CVE-2023-28422 Moyenne · 4,4
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

Event Manager for WooCommerce <= 3.8.6 – Authenticated (Administrator+) Stored Cross-Site Scripting via 'mep_get_option' function

The Event Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mep_get_option' function in versions up to, and including, 3.8.6 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-3.8.6

Correctif

3.8.7

Publication

20/03/2023

CVE-2022-47164 Moyenne · 4,3
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

Event Manager for WooCommerce <= 3.7.7 – Cross-Site Request Forgery leading to Uninstall Form Submission

The Event Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.7. This is due to missing or incorrect nonce validation on the 'uninstall_reason_submission' function. This makes it possible…

Versions affectées

*-3.7.7

Correctif

3.7.8

Publication

16/03/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités