N/A
2026-02-17< 1.9.0
WP Event Aggregator <= 1.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
Minimum safe version
1.9.0
Update to 1.9.0 or later to address 4 fixable vulnerabilities
WP Event Aggregator <= 1.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
CVE-2025-24700
CVE-2024-38703
CVE-2024-31371