CVE-2025-12976
Events Manager – Calendar, Bookings, Tickets, and more!
Minimum safe version
7.2.3
Update to 7.2.3 or later to address 42 fixable vulnerabilities
CVE-2025-12408
CVE-2025-12407
Event Manager <= 7.0.3 - Reflected Cross-Site Scripting via `calendar_header` Parameter
Events Manager <= 7.0.3 - Unauthenticated SQL Injection via `orderby` Parameter
Events Manager <= 7.0.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes
CVE-2025-1249
CVE-2024-11260
WordPress Events Manager Plugin <= 6.4.8 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-3492
CVE-2024-30515
CVE-2024-30421
CVE-2024-2111
CVE-2024-2110
CVE-2024-0614
CVE-2023-48326
Events Manager < 5.9.7.2 - CSV Injection
Events Manager <= 5.9.7.1 - CSV Injection
Events Manager < 5.9.7.2 & Events Manager Pro < 2.6.7.2 - Unauthenticated CSV Injection
WordPress Events Manager Plugin <= 5.3.5 - Multiple Cross Site Scripting
WordPress Events Manager Plugin <= 5.3.8 - Cross Site Scripting
WordPress Events Manager Plugin <= 5.5.1 - Cross Site Scripting
WordPress Events Manager plugin <= 5.9.7.1 - CSV Injection vulnerability
WordPress Events Manager plugin <= 5.9.8.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
WordPress Events Manager plugin <= 5.9.7.3 - SQL Injection (SQLi) vulnerability
WordPress Events Manager plugin <= 5.9.7.3 - Cross-Site Scripting (XSS) vulnerability
Events Manager < 5.3.5 & Events Manager Pro < 2.2.9 - Cross-Site Scripting
WordPress Events Manager plugin <=5.8.1.1 - Unauthenticated Stored XSS vulnerability
CVE-2018-0576
CVE-2018-13137
CVE-2015-9300
CVE-2015-9297
CVE-2015-9299
CVE-2015-9298
CVE-2012-6716
CVE-2013-7478
CVE-2013-7480
CVE-2013-7479
CVE-2013-7477
CVE-2019-16523
CVE-2020-35037
CVE-2020-35012