← WordPress Vulnerabilities
WordPress security by component

Event Monster – Event Manager, Ticket Booking & Registration

Event Monster – Event Manager, Ticket Booking & Registration is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Jun 06, 2026; the highest CVE/CNA score is 7.5.

Plugin slug: event-monster

CVE-2026-8608: Event Monster – Event Manager, Ticket Booking & Registration: A security weakness

Event Monster – Event Manager, Ticket Booking & Registration is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.1.0.

PublishedJun 06, 2026
Known safe version> 2.1.0
Safe version
Jun 06, 2026 CVE-2026-8608
Event Monster – Event Manager, Ticket Booking & Registration: A security weakness
Event Monster – Event Manager, Ticket Booking & Registration is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.1.0.
> 2.1.0
CVE5.3
NVDPending
Jan 14, 2025 CVE-2024-11396
Event Monster – Event Management, Tickets Booking, Upcoming Event: A security weakness
Event Monster – Event Management, Tickets Booking, Upcoming Event is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jun 21, 2024 CVE-2024-5059
Event Management Tickets Booking: A security weakness
Event Management Tickets Booking is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD7.5
Apr 30, 2024 CVE-2024-1895
Event Monster – Event Management, Tickets Booking, Upcoming Event: Code execution
Event Monster – Event Management, Tickets Booking, Upcoming Event is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.5
NVDPending
Dec 21, 2023 CVE-2023-47525
Event Monster – Event Management, Tickets Booking, Upcoming Event: Cross-site scripting
Event Monster – Event Management, Tickets Booking, Upcoming Event is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD5.4
Nov 21, 2022 CVE-2022-3720
Event Monster: SQL injection
Event Monster is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVD7.2
Nov 21, 2022 CVE-2022-3336
Event Monster: Cross-site request forgery
Event Monster is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3