← WordPress Vulnerabilities
WordPress security by component

Events Made Easy

Events Made Easy (events-made-easy) is a WordPress plugin with 10 published CVE records in this archive. The latest tracked vulnerability was published Aug 24, 2026; the highest published CVSS base score is 9.8.

Plugin slug: events-made-easy

CVE-2026-28162: Events Made Easy permits unauthenticated cross-site scripting

Events Made Easy through 3.2.5 accepts unauthenticated attacker-controlled input that reaches browser output without adequate neutralization. A victim must visit or interact with the affected content for script to execute in the site's origin, allowing access to data and actions available to that browser session.

PublishedAug 24, 2026
Known safe version3.2.6
Published vulnerabilities for events-made-easy
Safe version
Aug 24, 2026 CVE-2026-28162
Events Made Easy permits unauthenticated cross-site scripting
Events Made Easy through 3.2.5 accepts unauthenticated attacker-controlled input that reaches browser output without adequate neutralization. A victim must visit or interact with the affected content for script to execute in the site's origin, allowing access to data and actions available to that browser session.
3.2.6
CVE7.1
NVDPending
Aug 20, 2026 CVE-2026-75963
Events Made Easy Contributors can store a local-file-inclusion payload
Events Made Easy through 3.2.5 lets a Contributor or higher store a traversal value that reaches the eme_single_event_page_template function. When any visitor opens the affected single-event page, the stored value can include and execute an arbitrary PHP file already present on the server. This can expose local data, bypass access controls or execute the PHP file's code; obtaining a suitable PHP file is an additional prerequisite where one is not already available.
3.2.6
CVE7.5
NVDPending
Aug 06, 2026 CVE-2026-14842
Events Made Easy permits payment-token binding bypass
Events Made Easy before 3.1.2 does not bind a payment authorization token to the payment record being charged. An unauthenticated attacker can pay a small amount for a low-cost booking, then apply that authorization to a separate higher-priced booking; the plugin accepts the mismatched token and marks the expensive booking fully paid. The payment endpoint, action, token and booking parameters, gateway and validation function are not disclosed. Version 3.1.2 adds price checks for charging and notifications.
3.1.2
CVE5.3
NVDPending
Jul 31, 2026 CVE-2026-14843
Events Made Easy public nonce permits cross-record personal-data overwrite
Events Made Easy before 3.1.4 accepts an unauthenticated data-change request using a public nonce but does not require a per-record token or verify that the requester may modify the selected person record. A visitor can submit another person's record identifier with attacker-controlled personal data, overwriting that record. The published.
3.1.4
CVE5.3
NVDPending
Jul 27, 2026 CVE-2026-59557
Events Made Easy exposes an unauthenticated privileged operation
Events Made Easy through 3.1.3 permits an unauthenticated request to reach a plugin operation without the required access-control check.
3.1.4
CVE6.5
NVDPending
Mar 22, 2023 CVE-2023-28660
Events Made Easy: SQL injection
Events Made Easy is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVEPending
NVD8.8
Jan 19, 2023 CVE-2023-0404
Events Made Easy: A security weakness
Events Made Easy is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD5.4
Jun 20, 2022 CVE-2022-1905
Events Made Easy: SQL injection
Events Made Easy is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVEPending
NVD9.8
Jan 03, 2022 CVE-2021-25030
Events Made Easy: SQL injection
Events Made Easy is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVEPending
NVD8.8
Nov 01, 2021 CVE-2021-24813
Events Made Easy: Cross-site scripting
Events Made Easy is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD4.8