Event Espresso operates a WordPress-based event-management plugin portfolio, with its vulnerability footprint centered on SQL injection, cross-site request forgery, and cross-site scripting flaws across variants including the full Event Espresso suite and lighter Lite and Decaf editions. These input-handling and authorization weaknesses are typical of web-application plugins that process user-submitted event data and manage administrative workflows. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eventespresso over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-26153MEDIUM A cross-site scripting (XSS) vulnerability in wp-content/plugins/event-espresso-core-reg/admin_pages/messages/templates/ee_msg_admin_overview.template.php in the Event Espresso Cor | Jul 13, 2021 | 6.1 | 30 | NO | YES |
CVE-2017-14760CRITICAL SQL Injection exists in /includes/event-management/index.php in the event-espresso-free (aka Event Espresso Lite) plugin v3.1.37.12.L for WordPress via the recurrence_id parameter | Sep 27, 2017 | 9.8 | 29 | NO | NO |
CVE-2017-1002026HIGH Vulnerability in wordpress plugin Event Expresso Free v3.1.37.11.L, The function edit_event_category does not sanitize user-supplied input via the $id parameter before passing it i | Sep 14, 2017 | 8.8 | 26 | NO | NO |
CVE-2025-68007MEDIUM Missing Authorization vulnerability in Event Espresso Event Espresso 4 Decaf event-espresso-decaf allows Exploiting Incorrectly Configured Access Control Security Levels.This issue | Jan 22, 2026 | 6.5 | 25 | NO | NO |
CVE-2021-4404MEDIUM The Event Espresso 4 Decaf plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.10.11. This is due to missing or incorrect nonce val | Jul 1, 2023 | 4.3 | 16 | NO | NO |
CVE-2024-56251MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Event Espresso Event Espresso 4 Decaf event-espresso-decaf allows Cross Site Request Forgery.This issue affects Event Espresso 4 | Jan 2, 2025 | 4.3 | 15 | NO | NO |
CVE-2024-6883MEDIUM The Event Espresso 4 Decaf – Event Registration Event Ticketing plugin for WordPress is vulnerable to limited unauthorized plugin settings modification due to a missing capability | Aug 21, 2024 | 4.3 | 15 | NO | NO |
Missing Authorization vulnerability in Event Espresso Event Espresso 4 Decaf allows Functionality Misuse.This issue affects Event Espresso 4 Decaf: from n/a through 4.10.44.Decaf. | Jun 3, 2024 | 3.7 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eventespresso.
Media articles that mention a CVE ID that affects a product developed by Eventespresso — matched by CVE ID, not by vendor name.