Plugin Vulnerability Hub
Plugin 32 known issues Latest disclosed Dec 17, 2025

Events Manager – Calendar, Bookings, Tickets, and more! Vulnerabilities

Review known vulnerability records for the WordPress plugin Events Manager – Calendar, Bookings, Tickets, and more! (`events-manager`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2025-12976, CVE-2025-12407 and CVE-2025-12408, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
32
High or Critical
4
Patch Coverage
100%
Last Updated
Dec 18, 2025
Priority CVE Quick Links

Fast paths into Events Manager – Calendar, Bookings, Tickets, and more! CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
31
CVE-2015-9298 Critical 5.6
CVE-2015-9298 Events Manager – Calendar, Bookings, Tickets, and more! Vulnerability

Events Manager <= 5.5.7.1 - Code Injection

CVE-2025-6970 High 6.6.5
CVE-2025-6970 Events Manager – Calendar, Bookings, Tickets, and more! SQL Injection

Events Manager <= 7.0.3 - Unauthenticated SQL Injection via `orderby` Parameter

CVE-2024-11260 High 6.6.4
CVE-2024-11260 Events Manager – Calendar, Bookings, Tickets, and more! SQL Injection

Events Manager – Calendar, Bookings, Tickets, and more! <= 6.6.3 - Unauthenticated SQL Injection via Event Status Parameter

CVE-2020-35012 High 5.9.8
CVE-2020-35012 Events Manager – Calendar, Bookings, Tickets, and more! SQL Injection

Events Manager <= 5.9.7.3 - Admin+ SQL Injection

CVE-2025-12976 Medium 7.2.3
CVE-2025-12976 Events Manager – Calendar, Bookings, Tickets, and more! Stored Cross-Site Scripting

Events Manager <= 7.2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'events_list_grouped' Shortcode

CVE-2025-6976 Medium 6.6.5
CVE-2025-6976 Events Manager – Calendar, Bookings, Tickets, and more! Stored Cross-Site Scripting

Events Manager <= 7.0.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes

CVE-2024-3492 Medium 6.4.8
CVE-2024-3492 Events Manager – Calendar, Bookings, Tickets, and more! Stored Cross-Site Scripting

Events Manager – Calendar, Bookings, Tickets, and more! <= 6.4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via event, location, and event_category Shortcodes

CVE-2024-2111 Medium 6.4.7.2
CVE-2024-2111 Events Manager – Calendar, Bookings, Tickets, and more! Stored Cross-Site Scripting

Events Manager <= 6.4.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Events Manager – Calendar, Bookings, Tickets, and more! so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
32 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
1 critical and 3 high severity findings.
Recent CVEs
CVE-2025-12976, CVE-2025-12407 and CVE-2025-12408
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Events Manager – Calendar, Bookings, Tickets, and more!

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2025-12976
CVE-2025-12976: Events Manager <= 7.2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'events_list_grouped' Shortcode

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list_grouped' shortcode in all versions up to, and including, 7.2.2.1 due to insufficient input sanitization and output escaping...

Published
Dec 17, 2025
Patched Release
7.2.3
Affected Versions
Versions up to 7.2.2.1
Next Step
Update to 7.2.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-12407
CVE-2025-12407: Events Manager – Calendar, Bookings, Tickets, and more! <= 7.2.2.2 - Cross-Site Request Forgery to Location Deletion

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.2.2. This is due to missing or incorrect nonce validation on the 'location_delete' action. This makes it possible...

Published
Dec 11, 2025
Patched Release
7.2.2.3
Affected Versions
Versions up to 7.2.2.2
Next Step
Update to 7.2.2.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-12408
CVE-2025-12408: Events Manager <= 7.2.2.2 - Unauthenticated Information Exposure

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 7.2.2.2 via the 'get_location' action due to insufficient restrictions on which locations can be included. This makes it po...

Published
Dec 11, 2025
Patched Release
7.2.2.3
Affected Versions
Versions up to 7.2.2.2
Next Step
Update to 7.2.2.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-6976
CVE-2025-6976: Events Manager <= 7.0.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escaping on user supplied attrib...

Published
Jul 09, 2025
Patched Release
6.6.5
Affected Versions
Versions up to 6.6.4.4
Next Step
Update to 6.6.5 or newer if supported.
Plugin High Patched: Yes CVE-2025-6970
CVE-2025-6970: Events Manager <= 7.0.3 - Unauthenticated SQL Injection via `orderby` Parameter

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient pr...

Published
Jul 09, 2025
Patched Release
6.6.5
Affected Versions
Versions up to 6.6.4.4
Next Step
Update to 6.6.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-6975
CVE-2025-6975: Event Manager <= 7.0.3 - Reflected Cross-Site Scripting via `calendar_header` Parameter

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘calendar_header’ parameter in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escaping. This makes...

Published
Jul 09, 2025
Patched Release
6.6.5
Affected Versions
Versions up to 6.6.4.4
Next Step
Update to 6.6.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-1249
CVE-2025-1249: Events Manager – Calendar, Bookings, Tickets, and more! <= 6.6.4.1 - Missing Authorization

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.6.4.1. This makes it possible for unauthenticated attackers to perform an...

Published
Feb 26, 2025
Patched Release
6.6.4.2
Affected Versions
Versions up to 6.6.4.1
Next Step
Update to 6.6.4.2 or newer if supported.
Plugin High Patched: Yes CVE-2024-11260
CVE-2024-11260: Events Manager – Calendar, Bookings, Tickets, and more! <= 6.6.3 - Unauthenticated SQL Injection via Event Status Parameter

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficien...

Published
Feb 20, 2025
Patched Release
6.6.4
Affected Versions
Versions up to 6.6.3
Next Step
Update to 6.6.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-5889
CVE-2024-5889: Events Manager <= 6.4.8 - Reflected Cross-Site Scripting

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This makes it possi...

Published
Jun 28, 2024
Patched Release
6.4.9
Affected Versions
Versions up to 6.4.8
Next Step
Update to 6.4.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-3492
CVE-2024-3492: Events Manager – Calendar, Bookings, Tickets, and more! <= 6.4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via event, location, and event_category Shortcodes

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' shortcodes in all versions up to, and including, 6.4.7.3 due to insufficient input sanitization...

Published
Jun 11, 2024
Patched Release
6.4.8
Affected Versions
Versions up to 6.4.7.3
Next Step
Update to 6.4.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-30421
CVE-2024-30421: Events Manager <= 6.4.7.1 - Cross-Site Request Forgery

The Events Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.7.1. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged...

Published
Mar 28, 2024
Patched Release
6.4.7.2
Affected Versions
Versions up to 6.4.7.1
Next Step
Update to 6.4.7.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-30515
CVE-2024-30515: Events Manager <= 6.4.6.4 - Missing Authorization

The Events Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 6.4.6.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.

Published
Mar 28, 2024
Patched Release
6.4.7
Affected Versions
Versions up to 6.4.6.4
Next Step
Update to 6.4.7 or newer if supported.