← WordPress Vulnerabilities
WordPress security by component

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Jul 16, 2025; the highest CVE/CNA score is 8.1.

Plugin slug: wp-event-manager

CVE-2025-2800: WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce: Cross-site scripting

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedJul 16, 2025
Safe version guidanceSee mitigation notes
Safe version
Jul 16, 2025 CVE-2025-2800
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce: Cross-site scripting
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Jul 16, 2025 CVE-2025-2799
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce: Cross-site scripting
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce is affected by cross-site scripting. Exploitation requires at least administrator-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.8
Jun 09, 2025 CVE-2025-48125
WP Event Manager: Filesystem traversal
WP Event Manager is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.1
NVDPending
Apr 04, 2025 CVE-2025-32225
WP Event Manager: A security weakness
WP Event Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jul 16, 2024 CVE-2024-2691
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce: Cross-site scripting
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-0976
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce: Cross-site scripting
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Dec 15, 2023 CVE-2023-49181
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce: Cross-site scripting
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD5.4
Nov 13, 2023 CVE-2023-47697
Wp Event Manager: Cross-site scripting
Wp Event Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Sep 27, 2023 CVE-2023-4423
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce: Cross-site scripting
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.8
Jul 11, 2022 CVE-2022-1474
WP Event Manager: Cross-site scripting
WP Event Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Mar 07, 2022 CVE-2021-24810
WP Event Manager: Cross-site scripting
WP Event Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8