Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

WP Event Manager — Vulnerabilities & Security Advisories 6

Browse all 6 CVE security advisories affecting WP Event Manager. AI-powered Chinese analysis, POCs, and references for each vulnerability.

WP Event Manager is a WordPress plugin designed for event management and registration. Historically, it has been susceptible to multiple security vulnerabilities including remote code execution, cross-site scripting, and privilege escalation, with six CVEs documented. The plugin's complex functionality involving file handling and user input processing has created attack vectors. Notable security characteristics include insufficient input validation and inadequate access controls in versions prior to 3.1.37, which allowed authenticated users to execute unauthorized actions. While recent versions have addressed many issues, the plugin's history of vulnerabilities highlights the importance of maintaining updated installations to prevent potential compromises.

Found 2 results / 6 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2023-49181 WordPress WP Event Manager Plugin <= 3.1.40 is vulnerable to Cross Site Scripting (XSS) — WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce CWE-79 5.9 Medium 2023-12-15
CVE-2023-47697 WordPress WP Event Manager Plugin <= 3.1.39 is vulnerable to Cross Site Scripting (XSS) — WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce CWE-79 7.1 High 2023-11-13

This page lists every published CVE security advisory associated with WP Event Manager. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.