WordPress Events Made Easy Plugin <= 2.3.14 is vulnerable to SQL Injection
Events Made Easy
Minimum safe version
3.0.56
Update to 3.0.56 or later to address 13 fixable vulnerabilities
CVE-2023-0404
Events Made Easy < 1.5.50 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Events Made Easy < 1.5.50 - Multi CSRF to Stored Cross-Site Scripting & Event Deletion
Events Made Easy < 1.6.21 - CSRF to Cross-Site Scripting (XSS)
Events Made Easy <= 1.6.20 - Stored Cross-Site Scripting
WordPress Events Made Easy Plugin <= 2.3.16 is vulnerable to Privilege Escalation
Events Made Easy <= 2.3.16 - Missing Authorization
WordPress Events Made Easy Plugin <= 2.2.80 is vulnerable to SQL Injection
WordPress Events Made Easy Plugin <= 1.5.49 - Multiple Vulnerabilities
WordPress Events Made Easy Plugin <= 1.6.20 - Cross Site Scripting
CVE-2021-24813
CVE-2021-25030