WP Eventmanager provides WordPress event-management plugins that extend the platform's functionality for organizing and promoting events, positioning the vendor within a widely adopted content-management ecosystem. The vendor's disclosure history centers on its core WP Event Manager product alongside related plugins for event banners and user profiles, addressing the plugin-oriented attack surface typical of extensible CMS platforms. Current exploitation activity, severity distribution, and detailed exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wp Eventmanager over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24252HIGH The Event Banner WordPress plugin through 1.3 does not verify the uploaded image file, allowing admin accounts to upload arbitrary files, such as .exe, .php, or others executable, | May 6, 2021 | 7.2 | 24 | NO | NO |
CVE-2025-2800MEDIUM The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘organizer_name' para | Jul 16, 2025 | 6.1 | 20 | NO | NO |
CVE-2023-47697MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Event Manager WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin <= 3.1.39 ver | Nov 13, 2023 | 6.1 | 20 | NO | NO |
CVE-2022-1474MEDIUM The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in an attribute on the event dashboard, leading to a Reflected | Jul 11, 2022 | 6.1 | 20 | NO | NO |
CVE-2021-24810MEDIUM The WP Event Manager WordPress plugin before 3.1.23 does not escape some of its Field Editor settings when outputting them, allowing high privilege users to perform Cross-Site Scri | Mar 7, 2022 | 4.8 | 19 | NO | NO |
CVE-2024-0976MEDIUM The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the plugin parameter i | Mar 13, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-2691MEDIUM The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events' sho | Jul 16, 2024 | 5.4 | 17 | NO | NO |
CVE-2023-52118MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Event Manager WP User Profile Avatar allows Stored XSS.This issue affects W | Feb 1, 2024 | 5.4 | 17 | NO | NO |
CVE-2023-4423MEDIUM The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version | Sep 27, 2023 | 4.8 | 17 | NO | NO |
CVE-2023-6384MEDIUM The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar | Jan 22, 2024 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wp Eventmanager.
Media articles that mention a CVE ID that affects a product developed by Wp Eventmanager — matched by CVE ID, not by vendor name.