Eventbee RSVP Widget
Eventbee RSVP Widget has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Eventbee RSVP Widget has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by theviper17y. Eventbee RSVP Widget is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-31838Eventbee RSVP Widget <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Eventbee RSVP Widget
Author
eventbee
Eventbee RSVP registration widget plugin is a great solution for Event Managers who wish to have RSVP registration Widget on their WordPress sites. Eventbee RSVP registration widget appropriately blends with any type of themes and the widget can be placed anywhere according to the user’s wish. Using this widget an attendee can register for the event by filling up the profile and confirm for the event. Arbitrary section Manager can control who to register for the event. Manager can ask questions apart from default one. Manager can customize the look and feel of the widget according to the site. A brief Markdown Example If your event ID is 1234567890, in the page where you want to place the widget, just put [eventbeersvpwidget id=”1234567890″] It will display widget with a default width of 700px To display with a different width (say 800px), use [eventbeersvpwidget id=”1234567890″ width=”800″] Or you may visit your event manage console in eventbee.com, go to Integration and get wordpress widget code.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C