← WordPress Vulnerabilities
WordPress security by component

EKC Tournament Manager

EKC Tournament Manager is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published May 15, 2025; the highest CVE/CNA score is 9.6.

Plugin slug: ekc-tournament-manager

CVE-2024-9765: EKC Tournament Manager: A security weakness

EKC Tournament Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedMay 15, 2025
Safe version guidanceSee mitigation notes
Safe version
May 15, 2025 CVE-2024-9765
EKC Tournament Manager: A security weakness
EKC Tournament Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
May 15, 2025 CVE-2024-9711
EKC Tournament Manager: Cross-site request forgery
EKC Tournament Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVDPending
May 15, 2025 CVE-2024-9709
EKC Tournament Manager: Cross-site request forgery
EKC Tournament Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVDPending
Oct 31, 2024 CVE-2024-49674
EKC Tournament Manager: Dangerous file upload
EKC Tournament Manager is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE9.6
NVDPending