Plugin Vulnerability Hub
Plugin 43 known issues Latest disclosed May 25, 2026

EventPrime – Events Calendar, Bookings and Tickets Vulnerabilities

Review known vulnerability records for the WordPress plugin EventPrime – Events Calendar, Bookings and Tickets (`eventprime-event-calendar-management`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-42687, CVE-2026-42686 and CVE-2026-42669, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
43
High or Critical
3
Patch Coverage
100%
Last Updated
Jun 01, 2026
Related Security Guides

Use these guides while reviewing EventPrime – Events Calendar, Bookings and Tickets fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize EventPrime – Events Calendar, Bookings and Tickets remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
41
1. Match the Package
Confirm the installed WordPress plugin slug is eventprime-event-calendar-management before acting on any CVE from this cluster.
2. Sort by Severity
Start with 3 high or critical records, then review medium and unrated findings with public references.
3. Check Patch Evidence
43 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into EventPrime – Events Calendar, Bookings and Tickets CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
42
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2026-42687
EventPrime – Events Calendar, Bookings and Tickets <= 4.3.2.1 - Unauthenticated PHP...
Vulnerability Versions up to 4.3.2.1 4.3.2.2 CVSS 8.1
CVE-2026-24378
EventPrime – Events Calendar, Bookings and Tickets <= 4.2.8.0 - Unauthenticated PHP...
Vulnerability Versions up to 4.2.8.0 4.2.8.1 CVSS 8.1
CVE-2024-12024
EventPrime – Events Calendar, Bookings and Tickets <= 4.0.7.3 - Unauthenticated Stor...
Stored Cross-Site Scripting Versions up to 4.0.7.3 4.0.7.4 CVSS 7.2
CVE-2024-1320
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.3 - Unauthenticated Stored...
Stored Cross-Site Scripting Versions up to 3.4.3 3.4.4 CVSS 6.5
CVE-2024-1123
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Missing Authorization...
Vulnerability Versions up to 3.4.2 3.4.3 CVSS 6.5
CVE-2026-42686
EventPrime – Events Calendar, Bookings and Tickets <= 4.3.2.1 - Authenticated (Subsc...
Stored Cross-Site Scripting Versions up to 4.3.2.1 4.3.2.2 CVSS 6.4
CVE-2024-9864
EventPrime – Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticat...
Stored Cross-Site Scripting Versions up to 4.0.4.7 4.0.4.8 CVSS 6.1
CVE-2024-9865
EventPrime – Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticat...
Stored Cross-Site Scripting Versions up to 4.0.4.7 4.0.4.8 CVSS 6.1
CVE-2026-42687 High 4.3.2.2
CVE-2026-42687 EventPrime – Events Calendar, Bookings and Tickets Vulnerability

EventPrime – Events Calendar, Bookings and Tickets <= 4.3.2.1 - Unauthenticated PHP Object Injection

CVE-2026-24378 High 4.2.8.1
CVE-2026-24378 EventPrime – Events Calendar, Bookings and Tickets Vulnerability

EventPrime – Events Calendar, Bookings and Tickets <= 4.2.8.0 - Unauthenticated PHP Object Injection

CVE-2024-12024 High 4.0.7.4
CVE-2024-12024 EventPrime – Events Calendar, Bookings and Tickets Stored Cross-Site Scripting

EventPrime – Events Calendar, Bookings and Tickets <= 4.0.7.3 - Unauthenticated Stored Cross-Site Scripting via Ticket Category and Ticket Type Name

CVE-2024-1320 Medium 3.4.4
CVE-2024-1320 EventPrime – Events Calendar, Bookings and Tickets Stored Cross-Site Scripting

EventPrime – Events Calendar, Bookings and Tickets <= 3.4.3 - Unauthenticated Stored Cross-Site Scripting

CVE-2024-1123 Medium 3.4.3
CVE-2024-1123 EventPrime – Events Calendar, Bookings and Tickets Vulnerability

EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Missing Authorization to Arbitrary Post Overwrite

CVE-2026-42686 Medium 4.3.2.2
CVE-2026-42686 EventPrime – Events Calendar, Bookings and Tickets Stored Cross-Site Scripting

EventPrime – Events Calendar, Bookings and Tickets <= 4.3.2.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting

CVE-2024-9864 Medium 4.0.4.8
CVE-2024-9864 EventPrime – Events Calendar, Bookings and Tickets Stored Cross-Site Scripting

EventPrime – Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting

CVE-2024-9865 Medium 4.0.4.8
CVE-2024-9865 EventPrime – Events Calendar, Bookings and Tickets Stored Cross-Site Scripting

EventPrime – Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting via Transaction Log

Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for EventPrime – Events Calendar, Bookings and Tickets so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
43 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 3 high severity findings.
Recent CVEs
CVE-2026-42687, CVE-2026-42686 and CVE-2026-42669
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for EventPrime – Events Calendar, Bookings and Tickets

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes CVE-2026-42687
CVE-2026-42687: EventPrime – Events Calendar, Bookings and Tickets <= 4.3.2.1 - Unauthenticated PHP Object Injection

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.3.2.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No know...

Published
May 25, 2026
Patched Release
4.3.2.2
Affected Versions
Versions up to 4.3.2.1
Next Step
Update to 4.3.2.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-42686
CVE-2026-42686: EventPrime – Events Calendar, Bookings and Tickets <= 4.3.2.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...

Published
May 24, 2026
Patched Release
4.3.2.2
Affected Versions
Versions up to 4.3.2.1
Next Step
Update to 4.3.2.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-42669
CVE-2026-42669: EventPrime – Events Calendar, Bookings and Tickets <= 4.3.2.0 - Missing Authorization

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.3.2.0. This makes it possible for unauthenticated attackers to perform an unauthori...

Published
May 12, 2026
Patched Release
4.3.2.1
Affected Versions
Versions up to 4.3.2.0
Next Step
Update to 4.3.2.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-39518
CVE-2026-39518: EventPrime – Events Calendar, Bookings and Tickets <= 4.3.0.0 - Authenticated (Subscriber+) Insecure Direct Object Reference

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.0.0 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with...

Published
Apr 20, 2026
Patched Release
4.3.0.1
Affected Versions
Versions up to 4.3.0.0
Next Step
Update to 4.3.0.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-25312
CVE-2026-25312: EventPrime – Events Calendar, Bookings and Tickets <= 4.2.8.3 - Missing Authorization

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.8.3. This makes it possible for unauthenticated attackers to perform an unaut...

Published
Mar 18, 2026
Patched Release
4.2.8.4
Affected Versions
Versions up to 4.2.8.3
Next Step
Update to 4.2.8.4 or newer if supported.
Plugin High Patched: Yes CVE-2026-24378
CVE-2026-24378: EventPrime – Events Calendar, Bookings and Tickets <= 4.2.8.0 - Unauthenticated PHP Object Injection

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.8.0 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No know...

Published
Mar 17, 2026
Patched Release
4.2.8.1
Affected Versions
Versions up to 4.2.8.0
Next Step
Update to 4.2.8.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-69358
CVE-2025-69358: EventPrime – Events Calendar, Bookings and Tickets <= 4.2.6.0 - Missing Authorization

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.6.0. This makes it possible for unauthenticated attackers to perform an unaut...

Published
Mar 10, 2026
Patched Release
4.2.7.0
Affected Versions
Versions up to 4.2.6.0
Next Step
Update to 4.2.7.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-25389
CVE-2026-25389: EventPrime <= 4.2.8.3 - Unauthenticated Information Exposure

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.8.3. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

Published
Feb 20, 2026
Patched Release
4.2.8.4
Affected Versions
Versions up to 4.2.8.3
Next Step
Update to 4.2.8.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-1655
CVE-2026-1655: EventPrime <= 4.2.8.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Event Modification via 'event_id' Parameter

The EventPrime plugin for WordPress is vulnerable to unauthorized post modification due to missing authorization checks in all versions up to, and including, 4.2.8.4. This is due to the save_frontend_event_submission function accepting a user-controlled event_id parameter and upd...

Published
Feb 17, 2026
Patched Release
4.2.8.5
Affected Versions
Versions up to 4.2.8.4
Next Step
Update to 4.2.8.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-1657
CVE-2026-1657: EventPrime <= 4.2.8.4 - Missing Authorization to Unauthenticated Image Upload via 'ep_upload_file_media' AJAX Endpoint

The EventPrime plugin for WordPress is vulnerable to unauthorized image file upload in all versions up to, and including, 4.2.8.4. This is due to the plugin registering the upload_file_media AJAX action as publicly accessible (nopriv-enabled) without implementing any authenticati...

Published
Feb 16, 2026
Patched Release
4.2.8.5
Affected Versions
Versions up to 4.2.8.4
Next Step
Update to 4.2.8.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-24380
CVE-2026-24380: EventPrime <= 4.2.8.0 - Missing Authorization

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.8.0. This makes it possible for unauthenticated attackers to perform an unaut...

Published
Jan 28, 2026
Patched Release
4.2.8.1
Affected Versions
Versions up to 4.2.8.0
Next Step
Update to 4.2.8.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-14507
CVE-2025-14507: EventPrime - Events Calendar, Bookings and Tickets <= 4.2.7.0 - Unauthenticated Sensitive Information Exposure via REST API

The EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.7.0 via the REST API. This makes it possible for unauthenticated attackers to extract sensitive booking data inclu...

Published
Jan 12, 2026
Patched Release
4.2.8.0
Affected Versions
Versions up to 4.2.7.0
Next Step
Update to 4.2.8.0 or newer if supported.