Plugin Vulnerability Hub
Plugin 32 known issues Latest disclosed Dec 17, 2025

Events Manager – Calendar, Bookings, Tickets, and more! Vulnerabilities

Review known vulnerability records for the WordPress plugin Events Manager – Calendar, Bookings, Tickets, and more! (`events-manager`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2025-12976, CVE-2025-12407 and CVE-2025-12408, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
32
High or Critical
4
Patch Coverage
100%
Last Updated
Dec 18, 2025
Related Security Guides

Use these guides while reviewing Events Manager – Calendar, Bookings, Tickets, and more! fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize Events Manager – Calendar, Bookings, Tickets, and more! remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
19
1. Match the Package
Confirm the installed WordPress plugin slug is events-manager before acting on any CVE from this cluster.
2. Sort by Severity
Start with 4 high or critical records, then review medium and unrated findings with public references.
3. Check Patch Evidence
32 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into Events Manager – Calendar, Bookings, Tickets, and more! CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
31
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2015-9298
Events Manager <= 5.5.7.1 - Code Injection
Vulnerability Versions before 5.6 5.6 CVSS 9.8
CVE-2025-6970
Events Manager <= 7.0.3 - Unauthenticated SQL Injection via `orderby` Parameter
SQL Injection Versions up to 6.6.4.4 6.6.5 CVSS 7.5
CVE-2024-11260
Events Manager – Calendar, Bookings, Tickets, and more! <= 6.6.3 - Unauthenticated S...
SQL Injection Versions up to 6.6.3 6.6.4 CVSS 7.5
CVE-2020-35012
Events Manager <= 5.9.7.3 - Admin+ SQL Injection
SQL Injection Versions up to 5.9.7.3 5.9.8 CVSS 7.2
CVE-2025-12976
Events Manager <= 7.2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting...
Stored Cross-Site Scripting Versions up to 7.2.2.1 7.2.3 CVSS 6.4
CVE-2025-6976
Events Manager <= 7.0.3 - Authenticated(Contributor+) Stored Cross-Site Scripting vi...
Stored Cross-Site Scripting Versions up to 6.6.4.4 6.6.5 CVSS 6.4
CVE-2024-3492
Events Manager – Calendar, Bookings, Tickets, and more! <= 6.4.7.3 - Authenticated (...
Stored Cross-Site Scripting Versions up to 6.4.7.3 6.4.8 CVSS 6.4
CVE-2024-2111
Events Manager <= 6.4.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Stored Cross-Site Scripting Versions up to 6.4.7.1 6.4.7.2 CVSS 6.4
CVE-2015-9298 Critical 5.6
CVE-2015-9298 Events Manager – Calendar, Bookings, Tickets, and more! Vulnerability

Events Manager <= 5.5.7.1 - Code Injection

CVE-2025-6970 High 6.6.5
CVE-2025-6970 Events Manager – Calendar, Bookings, Tickets, and more! SQL Injection

Events Manager <= 7.0.3 - Unauthenticated SQL Injection via `orderby` Parameter

CVE-2024-11260 High 6.6.4
CVE-2024-11260 Events Manager – Calendar, Bookings, Tickets, and more! SQL Injection

Events Manager – Calendar, Bookings, Tickets, and more! <= 6.6.3 - Unauthenticated SQL Injection via Event Status Parameter

CVE-2020-35012 High 5.9.8
CVE-2020-35012 Events Manager – Calendar, Bookings, Tickets, and more! SQL Injection

Events Manager <= 5.9.7.3 - Admin+ SQL Injection

CVE-2025-12976 Medium 7.2.3
CVE-2025-12976 Events Manager – Calendar, Bookings, Tickets, and more! Stored Cross-Site Scripting

Events Manager <= 7.2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'events_list_grouped' Shortcode

CVE-2025-6976 Medium 6.6.5
CVE-2025-6976 Events Manager – Calendar, Bookings, Tickets, and more! Stored Cross-Site Scripting

Events Manager <= 7.0.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes

CVE-2024-3492 Medium 6.4.8
CVE-2024-3492 Events Manager – Calendar, Bookings, Tickets, and more! Stored Cross-Site Scripting

Events Manager – Calendar, Bookings, Tickets, and more! <= 6.4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via event, location, and event_category Shortcodes

CVE-2024-2111 Medium 6.4.7.2
CVE-2024-2111 Events Manager – Calendar, Bookings, Tickets, and more! Stored Cross-Site Scripting

Events Manager <= 6.4.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for Events Manager – Calendar, Bookings, Tickets, and more! so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
32 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
1 critical and 3 high severity findings.
Recent CVEs
CVE-2025-12976, CVE-2025-12407 and CVE-2025-12408
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Events Manager – Calendar, Bookings, Tickets, and more!

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2025-12976
CVE-2025-12976: Events Manager <= 7.2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'events_list_grouped' Shortcode

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list_grouped' shortcode in all versions up to, and including, 7.2.2.1 due to insufficient input sanitization and output escaping...

Published
Dec 17, 2025
Patched Release
7.2.3
Affected Versions
Versions up to 7.2.2.1
Next Step
Update to 7.2.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-12407
CVE-2025-12407: Events Manager – Calendar, Bookings, Tickets, and more! <= 7.2.2.2 - Cross-Site Request Forgery to Location Deletion

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.2.2. This is due to missing or incorrect nonce validation on the 'location_delete' action. This makes it possible...

Published
Dec 11, 2025
Patched Release
7.2.2.3
Affected Versions
Versions up to 7.2.2.2
Next Step
Update to 7.2.2.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-12408
CVE-2025-12408: Events Manager <= 7.2.2.2 - Unauthenticated Information Exposure

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 7.2.2.2 via the 'get_location' action due to insufficient restrictions on which locations can be included. This makes it po...

Published
Dec 11, 2025
Patched Release
7.2.2.3
Affected Versions
Versions up to 7.2.2.2
Next Step
Update to 7.2.2.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-6976
CVE-2025-6976: Events Manager <= 7.0.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escaping on user supplied attrib...

Published
Jul 09, 2025
Patched Release
6.6.5
Affected Versions
Versions up to 6.6.4.4
Next Step
Update to 6.6.5 or newer if supported.
Plugin High Patched: Yes CVE-2025-6970
CVE-2025-6970: Events Manager <= 7.0.3 - Unauthenticated SQL Injection via `orderby` Parameter

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient pr...

Published
Jul 09, 2025
Patched Release
6.6.5
Affected Versions
Versions up to 6.6.4.4
Next Step
Update to 6.6.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-6975
CVE-2025-6975: Event Manager <= 7.0.3 - Reflected Cross-Site Scripting via `calendar_header` Parameter

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘calendar_header’ parameter in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escaping. This makes...

Published
Jul 09, 2025
Patched Release
6.6.5
Affected Versions
Versions up to 6.6.4.4
Next Step
Update to 6.6.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-1249
CVE-2025-1249: Events Manager – Calendar, Bookings, Tickets, and more! <= 6.6.4.1 - Missing Authorization

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.6.4.1. This makes it possible for unauthenticated attackers to perform an...

Published
Feb 26, 2025
Patched Release
6.6.4.2
Affected Versions
Versions up to 6.6.4.1
Next Step
Update to 6.6.4.2 or newer if supported.
Plugin High Patched: Yes CVE-2024-11260
CVE-2024-11260: Events Manager – Calendar, Bookings, Tickets, and more! <= 6.6.3 - Unauthenticated SQL Injection via Event Status Parameter

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficien...

Published
Feb 20, 2025
Patched Release
6.6.4
Affected Versions
Versions up to 6.6.3
Next Step
Update to 6.6.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-5889
CVE-2024-5889: Events Manager <= 6.4.8 - Reflected Cross-Site Scripting

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This makes it possi...

Published
Jun 28, 2024
Patched Release
6.4.9
Affected Versions
Versions up to 6.4.8
Next Step
Update to 6.4.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-3492
CVE-2024-3492: Events Manager – Calendar, Bookings, Tickets, and more! <= 6.4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via event, location, and event_category Shortcodes

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' shortcodes in all versions up to, and including, 6.4.7.3 due to insufficient input sanitization...

Published
Jun 11, 2024
Patched Release
6.4.8
Affected Versions
Versions up to 6.4.7.3
Next Step
Update to 6.4.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-30421
CVE-2024-30421: Events Manager <= 6.4.7.1 - Cross-Site Request Forgery

The Events Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.7.1. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged...

Published
Mar 28, 2024
Patched Release
6.4.7.2
Affected Versions
Versions up to 6.4.7.1
Next Step
Update to 6.4.7.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-30515
CVE-2024-30515: Events Manager <= 6.4.6.4 - Missing Authorization

The Events Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 6.4.6.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.

Published
Mar 28, 2024
Patched Release
6.4.7
Affected Versions
Versions up to 6.4.6.4
Next Step
Update to 6.4.7 or newer if supported.