Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

Events Manager – Calendar, Bookings, Tickets, and more! — Vulnerabilities & Security Advisories 12

All 12 CVE vulnerabilities found in Events Manager – Calendar, Bookings, Tickets, and more!, with AI-generated Chinese analysis, references, and POCs.

This page catalogs security vulnerabilities associated with the Events Manager – Calendar, Bookings, Tickets, and more! software, a widely used WordPress plugin developed by the vendor Embedded Logic. The collection includes known weak points categorized by their specific types and affected versions, providing a comprehensive overview of the security landscape surrounding this specific product. The data covers advisory reports and disclosures from the initial release through recent updates, ensuring that historical and current threats are documented for analysis. Visitors to this aggregation page can utilize the structured data to track the evolution of security advisories issued by the vendor over time. By examining the listed issues, users can gain a deeper understanding of common weakness classes that frequently affect this plugin, such as cross-site scripting or insecure direct object references. This resource also allows administrators and developers to look up the complete vulnerability history of Events Manager, enabling them to assess the severity of past incidents and apply appropriate patches or mitigation strategies. Understanding the specific flaws documented here is crucial for maintaining the integrity of websites relying on this booking and ticketing solution. The page serves as a neutral reference point for security researchers and site owners who need factual information about the known risks without unnecessary commentary or promotional content.

Vendor: netweblogic

CVE IDTitleCVSSSeverityPublished
CVE-2025-12976 Events Manager <= 7.2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'events_list_grouped' Shortcode CWE-79 6.4 Medium2025-12-18
CVE-2025-12408 Events Manager <= 7.2.2.2 - Unauthenticated Information Exposure CWE-200 5.3 Medium2025-12-12
CVE-2025-12407 Events Manager – Calendar, Bookings, Tickets, and more! <= 7.2.2.2 - Cross-Site Request Forgery to Location Deletion CWE-352 4.3 Medium2025-12-12
CVE-2025-6976 Events Manager <= 7.0.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes CWE-79 6.4 Medium2025-07-09
CVE-2025-6975 Event Manager <= 7.0.3 - Reflected Cross-Site Scripting via `calendar_header` Parameter CWE-79 6.1 Medium2025-07-09
CVE-2025-6970 Events Manager <= 7.0.3 - Unauthenticated SQL Injection via `orderby` Parameter CWE-89 7.5 High2025-07-09
CVE-2024-11260 Events Manager – Calendar, Bookings, Tickets, and more! <= 6.6.3 - Unauthenticated SQL Injection via Event Status Parameter CWE-89 7.5 High2025-02-21
CVE-2024-5889 Events Manager <= 6.4.8 - Reflected Cross-Site Scripting CWE-79 6.1 Medium2024-06-29
CVE-2024-3492 Events Manager – Calendar, Bookings, Tickets, and more! <= 6.4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via event, location, and event_category Shortcodes CWE-79 6.4 Medium2024-06-12
CVE-2024-2110 Events Manager <= 6.4.7.1 - Cross-Site Request Forgery CWE-352 4.3 Medium2024-03-28
CVE-2024-2111 Events Manager <= 6.4.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-03-28
CVE-2024-0614 Events Manager <= 6.4.6.4 - Authenticated(Administator+) Stored Cross-Site Scripting via settings CWE-79 4.4 Medium2024-03-13

All 12 known CVE vulnerabilities affecting Events Manager – Calendar, Bookings, Tickets, and more! with full Chinese analysis, references, and POCs where available.