Eventer - WordPress Event & Booking Manager Plugin

Eventer - WordPress Event & Booking Manager Plugin has 12 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; 10 are fixed and 2 remain unpatched as of September 2026. Their average CVSS score is 6.7, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 4 high. 2025 was the busiest year with 10 disclosures.

The most common weakness is Missing Authorization, behind 3 of the records (25%). Other recurring categories include SQL Injection, Cross-Site Scripting.

10 of the records (83%) have a vendor fix, while 2 remain unpatched. The oldest unresolved one dates back to 2025.

6 independent researchers contributed these findings, most of them (4) reported by István Márton.

Strategic Overview

Avg CVSSMedium
6.7/ 10
Patch Coverage83%
Open

2

Fixed

10

Get automatic notifications for all Eventer - WordPress Event & Booking Manager Plugin vulnerabilities before they are exploited.

Most severe open issueCVSS 7.5CVE-2025-39481

Eventer <= 3.9.6 - Unauthenticated SQL Injection

Read the full analysis

Vulnerability Records

12 records
2026-07-07 16:30CVE-2026-9700
7.5
High
Rafie MuhammadYes
2026-07-07 16:30CVE-2026-9701
9.8
Critical
Rafie MuhammadYes
2025-08-04 00:00CVE-2025-39483
6.5
Medium
BondsYes
2025-05-16 00:00CVE-2025-39481
7.5
High
Nguyễn Trung KiênNo
2025-05-16 00:00CVE-2025-39482
4.3
Medium
Nguyễn Trung KiênNo
2025-03-06 19:34CVE-2025-0959
8.8
High
Lucio SáYes
2025-02-14 00:00CVE-2025-22635
6.1
Medium
Nguyễn Trung KiênYes
2025-02-03 00:00CVE-2024-11133
5.3
Medium
István MártonYes
2025-02-03 00:00CVE-2024-11132
6.4
Medium
István MártonYes
2025-02-03 00:00CVE-2024-11134
4.3
Medium
István MártonYes
Showing 1–10 of 12 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C