← WordPress Vulnerabilities
WordPress security by component

EventPrime

EventPrime is a WordPress component with 16 published CVE records in this archive. The latest tracked vulnerability was published May 15, 2025; the highest CVE/CNA score is 6.5.

Plugin slug: eventprime

CVE-2024-4665: EventPrime: A security weakness

EventPrime is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedMay 15, 2025
Safe version guidanceSee mitigation notes
Safe version
May 15, 2025 CVE-2024-4665
EventPrime: A security weakness
EventPrime is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.4
NVDPending
Oct 24, 2024 CVE-2024-9865
EventPrime – Events Calendar, Bookings and Tickets: Cross-site scripting
EventPrime – Events Calendar, Bookings and Tickets is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 24, 2024 CVE-2024-9864
EventPrime – Events Calendar, Bookings and Tickets: Cross-site scripting
EventPrime – Events Calendar, Bookings and Tickets is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Oct 10, 2024 CVE-2024-47648
EventPrime: An open redirect
EventPrime is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
See mitigation notes
CVE4.7
NVD6.1
Mar 13, 2024 CVE-2024-1321
EventPrime – Events Calendar, Bookings and Tickets: A security weakness
EventPrime – Events Calendar, Bookings and Tickets is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Mar 13, 2024 CVE-2024-1126
EventPrime – Events Calendar, Bookings and Tickets: A security weakness
EventPrime – Events Calendar, Bookings and Tickets is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Mar 09, 2024 CVE-2024-1320
EventPrime – Events Calendar, Bookings and Tickets: Cross-site scripting
EventPrime – Events Calendar, Bookings and Tickets is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD6.1
Mar 09, 2024 CVE-2024-1125
EventPrime – Events Calendar, Bookings and Tickets: A security weakness
EventPrime – Events Calendar, Bookings and Tickets is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD5.3
Mar 09, 2024 CVE-2024-1124
EventPrime – Events Calendar, Bookings and Tickets: A security weakness
EventPrime – Events Calendar, Bookings and Tickets is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Mar 09, 2024 CVE-2024-1123
EventPrime – Events Calendar, Bookings and Tickets: A security weakness
EventPrime – Events Calendar, Bookings and Tickets is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Jan 22, 2024 CVE-2023-6447
EventPrime: A security weakness
EventPrime is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Nov 27, 2023 CVE-2023-4252
EventPrime: A security weakness
EventPrime is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Oct 31, 2023 CVE-2023-5519
EventPrime: Cross-site request forgery
EventPrime is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Oct 31, 2023 CVE-2023-5238
EventPrime: A security weakness
EventPrime is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.1
NVD6.1
Oct 31, 2023 CVE-2023-4251
EventPrime: Cross-site request forgery
EventPrime is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Oct 31, 2023 CVE-2023-4250
EventPrime: Cross-site scripting
EventPrime is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1