Magepeople develops a suite of WordPress and WooCommerce plugins focused on booking, ticketing, and event-management functionality, serving as extensions to e-commerce platforms. Its disclosed vulnerabilities center on cross-site scripting weaknesses in web-facing input and form-handling contexts, typical of plugin-layer integration points where user-supplied data flows through template rendering. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Magepeople over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0478HIGH The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statem | Mar 14, 2022 | 8.8 | 28 | NO | NO |
CVE-2024-24796HIGH Deserialization of Untrusted Data vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin.This issue affects Event | Feb 12, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-43138HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MagePeople Team Event Manager for WooCommerce allows PHP Local File Inclusion.This i | Aug 13, 2024 | 8.8 | 24 | NO | NO |
CVE-2022-47164HIGH Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.7.7 versions. | May 25, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-0144MEDIUM The Event Manager and Tickets Selling Plugin for WooCommerce WordPress plugin before 3.8.0 does not validate and escape some of its post meta before outputting them back in a page/ | Feb 6, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-4067MEDIUM The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_date' and 'tab_date_r' parameters in versions up to, | Aug 2, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-30496MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MagePeople Team WpBusTicketly plugin <= 5.2.5 versions. | Nov 22, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-28422MEDIUM Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce <= 3.8.6. versions. | Mar 23, 2023 | 4.8 | 18 | NO | NO |
CVE-2025-5568MEDIUM The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 4.4.2 due to insufficient input saniti | Jun 7, 2025 | 5.4 | 16 | NO | NO |
CVE-2024-43986MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagePeople Team Taxi Booking Manager for WooCommerce allows Stored XSS. | Aug 29, 2024 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Magepeople.
Media articles that mention a CVE ID that affects a product developed by Magepeople — matched by CVE ID, not by vendor name.