Skip to content
Noroxi

wp-eventmanager records

12 published records for vendor wp-eventmanager.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
16.7%
Median publish → KEV
No record has entered KEV

All records

12 records
  • Event Banner <= 1.3 - Arbitrary File Upload to RCE

    HighCVSS 7.2No exploitEPSS 2%

    wp-eventmanager · event bannerMay 6, 2021

  • CVE-2022-1474
    24Monitor

    WP Event Manager < 3.1.28 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 1%

    wp-eventmanager · wp event managerJul 11, 2022

  • CVE-2024-0976
    24Monitor

    WP Event Manager <= 3.1.41 - Reflected Cross-Site Scripting via plugin

    MediumCVSS 6.1No exploitEPSS 1%

    wp-eventmanager · wp event managerMar 13, 2024

  • WordPress WP Event Manager Plugin <= 3.1.39 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 0%

    wp-eventmanager · wp event managerNov 13, 2023

  • CVE-2025-2800
    24Monitor

    WP Event Manager <= 3.1.50 - Unauthenticated Stored Cross-Site Scripting via 'organizer_name'

    MediumCVSS 6.1No exploitEPSS 0%

    wp-eventmanager · wp event managerJul 16, 2025

  • WordPress WP Event Manager Plugin <= 3.1.40 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    wp-eventmanager · wp event managerDec 15, 2023

  • WordPress WP User Profile Avatar Plugin <= 1.0 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    wp-eventmanager · wp event managerFeb 1, 2024

  • CVE-2024-2691
    21Monitor

    WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce <= 3.1.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'event

    MediumCVSS 5.4No exploitEPSS 0%

    wp-eventmanager · wp event managerJul 16, 2024

  • WP Event Manager < 3.1.23 - Admin+ Stored Cross-Site Scripting

    MediumCVSS 4.8No exploitEPSS 1%

    wp-eventmanager · wp event managerMar 7, 2022

  • CVE-2023-4423
    19Monitor

    WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce <= 3.1.37.1 - Authenticated (Admin+) Stored Cross-Site Scripting

    MediumCVSS 4.8No exploitEPSS 1%

    wp-eventmanager · wp event managerSep 27, 2023

  • CVE-2025-2799
    19Monitor

    WP Event Manager <= 3.1.49 - Authenticated (Administrator+) Stored Cross-Site Scripting

    MediumCVSS 4.8No exploitEPSS 0%

    wp-eventmanager · wp event managerJul 16, 2025

  • CVE-2023-6384
    17Monitor

    WP User Profile Avatar < 1.0.1 - Author+ Avatar Deletion/Update via IDOR

    MediumCVSS 4.3No exploitEPSS 0%

    wp-eventmanager · user profile avatarJan 22, 2024