EKC Tournament Manager
EKC Tournament Manager has 4 disclosed vulnerabilities in the WordSec catalog, all reported in 2024; all 4 are fixed as of September 2026. Their average CVSS score is 5.6, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2024 was the busiest year with 4 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 3 of the records (75%). Other recurring categories include Path Traversal.
Every one of the 4 issues recorded for EKC Tournament Manager has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, most of them (3) reported by Vuln Seeker Cybersecurity Team. EKC Tournament Manager is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2024-49674EKC Tournament Manager <= 2.2.1 - Cross-Site Request Forgery to Arbitrary File Upload
Read the full analysisVulnerability Records

EKC Tournament Manager
Author
lukashuser
This plugin allows you to manage Swiss system style tournaments, including registration of teams and players. It is developed for and used at the EKC European Kubb Championships. This plugin provides support for Elementor and Contact Form 7 registration forms. Documentation Information about this plugin, including a step-by-step tutorial, is available at https://kubb.live/ekc-tournament-manager Technical documentation is available on Github. Source Code Source code on Github: https://github.com/LukasHuser/ekc-tournament-manager
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C