All 6 CVE vulnerabilities found in Eventer, with AI-generated Chinese analysis, references, and POCs.
Vendor: imithemes
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-9700 | Eventer <= 4.4.2 - Unauthenticated SQL Injection via 'code' Parameter CWE-89 | 7.5 | High | 2026-07-08 |
| CVE-2026-9701 | Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation CWE-289 | 9.8 | Critical | 2026-07-08 |
| CVE-2025-39483 | WordPress Eventer plugin < 3.9.9.1 - Content Injection vulnerability CWE-94 | 6.5 | Medium | 2025-08-14 |
| CVE-2025-39481 | WordPress Eventer plugin < 3.11.4 - SQL Injection vulnerability CWE-89 | 9.3 | Critical | 2025-05-16 |
| CVE-2025-39482 | WordPress Eventer plugin < 3.11.4 - Broken Access Control vulnerability CWE-862 | 4.3 | Medium | 2025-05-16 |
| CVE-2025-22635 | WordPress Eventer - WordPress Event & Booking Manager Plugin plugin < 3.9.9 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 | 7.1 | High | 2025-02-23 |
All 6 known CVE vulnerabilities affecting Eventer with full Chinese analysis, references, and POCs where available.