Medium 4.4
2025-07-16< 3.1.50
WP Event Manager <= 3.1.49 - Authenticated (Administrator+) Stored Cross-Site Scripting
Minimum safe version
3.2.1
Update to 3.2.1 or later to address 11 fixable vulnerabilities
WP Event Manager <= 3.1.49 - Authenticated (Administrator+) Stored Cross-Site Scripting
WP Event Manager <= 3.1.50 - Unauthenticated Stored Cross-Site Scripting via 'organizer_name'
CVE-2025-48125
CVE-2025-32225
CVE-2024-2691
CVE-2024-0976
CVE-2023-49181
CVE-2023-47697
WordPress WP Event Manager Plugin <= 3.1.37.1 is vulnerable to Cross Site Scripting (XSS)
CVE-2022-1474
CVE-2021-24810