← WordPress Vulnerabilities
WordPress security by component

Events Made Easy

Events Made Easy is a WordPress component with 6 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: events-made-easy

CVE-2026-59557: Events Made Easy exposes an unauthenticated privileged operation

Events Made Easy through 3.1.3 permits an unauthenticated request to reach a plugin operation without the required access-control check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.

PublishedJul 27, 2026
Known safe version3.1.4
Safe version
Jul 27, 2026 CVE-2026-59557
Events Made Easy exposes an unauthenticated privileged operation
Events Made Easy through 3.1.3 permits an unauthenticated request to reach a plugin operation without the required access-control check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.
3.1.4
CVE6.5
NVDPending
Mar 22, 2023 CVE-2023-28660
Events Made Easy: SQL injection
Events Made Easy is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8
Jan 19, 2023 CVE-2023-0404
Events Made Easy: A security weakness
Events Made Easy is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD5.4
Jun 20, 2022 CVE-2022-1905
Events Made Easy: SQL injection
Events Made Easy is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Jan 03, 2022 CVE-2021-25030
Events Made Easy: SQL injection
Events Made Easy is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8
Nov 01, 2021 CVE-2021-24813
Events Made Easy: Cross-site scripting
Events Made Easy is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8