← WordPress Vulnerabilities
WordPress security by component

Eventer

Eventer is a WordPress component with 12 published CVE records in this archive. The latest tracked vulnerability was published Jul 08, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: eventer

CVE-2026-9700: Eventer: SQL injection

Eventer is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 4.4.2.

PublishedJul 08, 2026
Known safe version> 4.4.2
Safe version
Jul 08, 2026 CVE-2026-9700
Eventer: SQL injection
Eventer is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 4.4.2.
> 4.4.2
CVE7.5
NVDPending
Jul 08, 2026 CVE-2026-9701
Eventer: SQL injection
Eventer is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 4.4.2.
> 4.4.2
CVE9.8
NVDPending
Aug 14, 2025 CVE-2025-39483
Eventer: Code execution
Eventer is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE6.5
NVDPending
May 16, 2025 CVE-2025-39482
Eventer: A security weakness
Eventer is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD8.8
May 16, 2025 CVE-2025-39481
Eventer: SQL injection
Eventer is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.3
NVD9.8
Mar 07, 2025 CVE-2025-0959
Eventer - WordPress Event & Booking Manager Plugin: SQL injection
Eventer - WordPress Event & Booking Manager Plugin is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD6.5
Feb 23, 2025 CVE-2025-22635
Eventer: Cross-site scripting
Eventer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Feb 03, 2025 CVE-2024-11134
Eventer: A security weakness
Eventer is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD6.5
Feb 03, 2025 CVE-2024-11133
Eventer: A security weakness
Eventer is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Feb 03, 2025 CVE-2024-11132
Eventer: Cross-site scripting
Eventer is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jan 28, 2025 CVE-2024-11135
Eventer: SQL injection
Eventer is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVD7.5
Jan 17, 2025 CVE-2024-10799
Eventer: Filesystem traversal
Eventer is affected by filesystem traversal. Exploitation requires at least subscriber-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE6.5
NVDPending