WordPress security by component
Events Made Easy
Events Made Easy (events-made-easy) is a WordPress plugin with 10 published CVE records in this archive. The latest tracked vulnerability was published Aug 24, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
events-made-easyLatest vulnerability
CVE-2026-28162: Events Made Easy permits unauthenticated cross-site scripting
Events Made Easy through 3.2.5 accepts unauthenticated attacker-controlled input that reaches browser output without adequate neutralization. A victim must visit or interact with the affected content for script to execute in the site's origin, allowing access to data and actions available to that browser session.
| Safe version |
|
||
|---|---|---|---|
| Aug 24, 2026 |
CVE-2026-28162
Events Made Easy permits unauthenticated cross-site scripting
Events Made Easy through 3.2.5 accepts unauthenticated attacker-controlled input that reaches browser output without adequate neutralization. A victim must visit or interact with the affected content for script to execute in the site's origin, allowing access to data and actions available to that browser session.
|
3.2.6 |
CVE7.1
NVDPending
|
| Aug 20, 2026 |
CVE-2026-75963
Events Made Easy Contributors can store a local-file-inclusion payload
Events Made Easy through 3.2.5 lets a Contributor or higher store a traversal value that reaches the eme_single_event_page_template function. When any visitor opens the affected single-event page, the stored value can include and execute an arbitrary PHP file already present on the server. This can expose local data, bypass access controls or execute the PHP file's code; obtaining a suitable PHP file is an additional prerequisite where one is not already available.
|
3.2.6 |
CVE7.5
NVDPending
|
| Aug 06, 2026 |
CVE-2026-14842
Events Made Easy permits payment-token binding bypass
Events Made Easy before 3.1.2 does not bind a payment authorization token to the payment record being charged. An unauthenticated attacker can pay a small amount for a low-cost booking, then apply that authorization to a separate higher-priced booking; the plugin accepts the mismatched token and marks the expensive booking fully paid. The payment endpoint, action, token and booking parameters, gateway and validation function are not disclosed. Version 3.1.2 adds price checks for charging and notifications.
|
3.1.2 |
CVE5.3
NVDPending
|
| Jul 31, 2026 |
CVE-2026-14843
Events Made Easy public nonce permits cross-record personal-data overwrite
Events Made Easy before 3.1.4 accepts an unauthenticated data-change request using a public nonce but does not require a per-record token or verify that the requester may modify the selected person record. A visitor can submit another person's record identifier with attacker-controlled personal data, overwriting that record. The published.
|
3.1.4 |
CVE5.3
NVDPending
|
| Jul 27, 2026 |
CVE-2026-59557
Events Made Easy exposes an unauthenticated privileged operation
Events Made Easy through 3.1.3 permits an unauthenticated request to reach a plugin operation without the required access-control check.
|
3.1.4 |
CVE6.5
NVDPending
|
| Mar 22, 2023 |
CVE-2023-28660
Events Made Easy: SQL injection
Events Made Easy is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Jan 19, 2023 |
CVE-2023-0404
Events Made Easy: A security weakness
Events Made Easy is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Jun 20, 2022 |
CVE-2022-1905
Events Made Easy: SQL injection
Events Made Easy is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD9.8
|
| Jan 03, 2022 |
CVE-2021-25030
Events Made Easy: SQL injection
Events Made Easy is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Nov 01, 2021 |
CVE-2021-24813
Events Made Easy: Cross-site scripting
Events Made Easy is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.8
|