Events Manager – Calendar, Bookings, Tickets, and more!

Vulnerabilities 42Slug events-managerLatest version 7.2.3.1WordPress.org →

Minimum safe version

7.2.3

Update to 7.2.3 or later to address 42 fixable vulnerabilities

Latest available7.2.3.1
Medium 5.3
2025-12-12< 7.2.2.3

CVE-2025-12408

Medium 4.3
2025-12-12< 7.2.2.3

CVE-2025-12407

Medium 6.1
2025-07-09< 6.6.5

Event Manager <= 7.0.3 - Reflected Cross-Site Scripting via `calendar_header` Parameter

High 7.5
2025-07-09< 6.6.5

Events Manager <= 7.0.3 - Unauthenticated SQL Injection via `orderby` Parameter

Medium 6.4
2025-07-09< 6.6.5

Events Manager <= 7.0.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes

Medium 6.1
2024-07-01< 6.4.9

WordPress Events Manager Plugin <= 6.4.8 is vulnerable to Cross Site Scripting (XSS)

N/A
< 5.9.7.2

Events Manager &lt; 5.9.7.2 - CSV Injection

N/A
2020-02-05< 5.9.7.2

Events Manager <= 5.9.7.1 - CSV Injection

N/A
2020-02-06< 5.9.7.2

Events Manager < 5.9.7.2 & Events Manager Pro < 2.6.7.2 - Unauthenticated CSV Injection

N/A
2015-05-15< 5.3.6

WordPress Events Manager Plugin <= 5.3.5 - Multiple Cross Site Scripting

N/A
2015-05-15< 5.3.9

WordPress Events Manager Plugin <= 5.3.8 - Cross Site Scripting

N/A
2015-05-15< 5.5.2

WordPress Events Manager Plugin <= 5.5.1 - Cross Site Scripting

N/A
2020-02-07< 5.9.7.2

WordPress Events Manager plugin <= 5.9.7.1 - CSV Injection vulnerability

N/A
2020-11-25< 5.9.8.2

WordPress Events Manager plugin <= 5.9.8.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability

N/A
2020-11-30< 5.9.8

WordPress Events Manager plugin <= 5.9.7.3 - SQL Injection (SQLi) vulnerability

N/A
2020-11-30< 5.9.8

WordPress Events Manager plugin <= 5.9.7.3 - Cross-Site Scripting (XSS) vulnerability

Medium 5.4
2018-03-28< 5.8.1.2

WordPress Events Manager plugin <=5.8.1.1 - Unauthenticated Stored XSS vulnerability