Medium 6.5
2026-01-22< 5.0.53.decaf
CVE-2025-68007
Minimum safe version
5.0.53.decaf
Update to 5.0.53.decaf or later to address 7 fixable vulnerabilities
CVE-2025-68007
WordPress Event Espresso 4 Decaf Plugin <= 5.0.28.decaf is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2024-6883
CVE-2021-4404
CVE-2021-4342
CVE-2023-27437
Multiple Plugins - CSRF Bypass
Various Affected Software (Various Versions) - Cross-Site Request Forgery Bypass
WordPress Event Espresso 4 Decaf plugin <= 4.10.12.decaf - Cross-Site Request Forgery (CSRF) vulnerability