Events Manager – Calendar, Bookings, Tickets, and more!

Events Manager – Calendar, Bookings, Tickets, and more! has 45 disclosed vulnerabilities in the WordSec catalog, reported between 2012 and 2026; all 45 are fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 8 high. 2026 was the busiest year with 11 disclosures.

The most common weakness is Cross-Site Scripting, behind 25 of the records (56%). Other recurring categories include SQL Injection, Cross-Site Request Forgery (CSRF).

Every one of the 45 issues recorded for Events Manager – Calendar, Bookings, Tickets, and more! has a vendor fix available, so running the current release closes all known holes.

27 independent researchers contributed these findings, most of them (3) reported by Jakub Herman. Events Manager – Calendar, Bookings, Tickets, and more! is installed on roughly 60,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

01234567891006.08.2008Today22.05.20126.1Events Manager < 5.1.7 - Cross-Site Scripting CVSS 6.1 · 22.05.201227.02.20136.1Events Manager <= 5.3.6 - Multiple Cross-Site Scripting CVSS 6.1 · 27.02.201314.08.20136.1Events Manager < 5.5 - Cross-Site Scripting CVSS 6.1 · 14.08.201301.08.20146.1Events Manager <= 5.5.1 - Multiple Cross-Site Scripting CVSS 6.1 · 01.08.20146.1Events Manager < 5.3.9 - Cross-Site Scripting CVSS 6.1 · 01.08.20146.1Events Manager < 5.3.5 & Events Manager Pro < 2.2.9 - Cross-Site Scripting CVSS 6.1 · 01.08.201423.05.20156.1Events Manager < 5.5.7 - Cross-Site Scripting CVSS 6.1 · 23.05.201504.06.20156.1Events Manager < 5.5.7.1 - Cross-Site Scripting CVSS 6.1 · 04.06.201510.08.20156.1Events Manager <= 5.5.7.1 - Cross-Site Scripting CVSS 6.1 · 10.08.20159.8Events Manager <= 5.5.7.1 - Code Injection CVSS 9.8 · 10.08.201526.03.20186.4Events Manager <= 5.8.1.1 - Cross-Site Scripting CVSS 6.4 · 26.03.201827.04.20185.4Events Manager <= 5.8.1.3 - Stored Cross-Site Scripting CVSS 5.4 · 27.04.201818.07.20184.8Events Manager <= 5.9.4 - Cross-Site Scripting CVSS 4.8 · 18.07.201816.10.20196.4Events Manager <= 5.9.5 - Authenticated Stored Cross-Site Scripting CVSS 6.4 · 16.10.201905.02.20205.5Events Manager <= 5.9.7.1 - CSV Injection CVSS 5.5 · 05.02.202006.02.20207.1Events Manager < 5.9.7.2 & Events Manager Pro < 2.6.7.2 - Unauthenticated CSV Injection CVSS 7.1 · 06.02.202007.06.20206.1Events Manager <= 5.9.7.3 - Cross-Site Scripting CVSS 6.1 · 07.06.20207.2Events Manager <= 5.9.7.3 - Admin+ SQL Injection CVSS 7.2 · 07.06.202023.11.20236.1Events Manager <= 6.4.5 - Reflected Cross-Site Scripting CVSS 6.1 · 23.11.202328.02.20244.4Events Manager <= 6.4.6.4 - Authenticated(Administator+) Stored Cross-Site Scripting via settings CVSS 4.4 · 28.02.202427.03.20244.3Events Manager <= 6.4.7.1 - Cross-Site Request Forgery CVSS 4.3 · 27.03.20246.4Events Manager <= 6.4.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 27.03.202428.03.20244.3Events Manager <= 6.4.7.1 - Cross-Site Request Forgery CVSS 4.3 · 28.03.20244.3Events Manager <= 6.4.6.4 - Missing Authorization CVSS 4.3 · 28.03.202411.06.20246.4Events Manager – Calendar, Bookings, Tickets, and more! <= 6.4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via event, location, and event_category Shortcodes CVSS 6.4 · 11.06.202428.06.20246.1Events Manager <= 6.4.8 - Reflected Cross-Site Scripting CVSS 6.1 · 28.06.202420.02.20257.5Events Manager – Calendar, Bookings, Tickets, and more! <= 6.6.3 - Unauthenticated SQL Injection via Event Status Parameter CVSS 7.5 · 20.02.202526.02.20255.3Events Manager – Calendar, Bookings, Tickets, and more! <= 6.6.4.1 - Missing Authorization CVSS 5.3 · 26.02.202509.07.20256.4Events Manager <= 7.0.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes CVSS 6.4 · 09.07.20257.5Events Manager <= 7.0.3 - Unauthenticated SQL Injection via `orderby` Parameter CVSS 7.5 · 09.07.20256.1Event Manager <= 7.0.3 - Reflected Cross-Site Scripting via `calendar_header` Parameter CVSS 6.1 · 09.07.202511.12.20255.3Events Manager <= 7.2.2.2 - Unauthenticated Information Exposure CVSS 5.3 · 11.12.20254.3Events Manager – Calendar, Bookings, Tickets, and more! <= 7.2.2.2 - Cross-Site Request Forgery to Location Deletion CVSS 4.3 · 11.12.202517.12.20256.4Events Manager <= 7.2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'events_list_grouped' Shortcode CVSS 6.4 · 17.12.202501.07.20267.5Events Manager <= 7.3.6 - Unauthenticated SQL Injection CVSS 7.5 · 01.07.202608.07.20268.1Events Manager – Calendar, Bookings, Tickets, and more! <= 7.3.6 - Unauthenticated PHP Object Injection CVSS 8.1 · 08.07.202630.07.20265.3Events Manager <= 7.3 - Unauthenticated Pending Upload Disclosure CVSS 5.3 · 30.07.202604.08.20267.2Events Manager – Calendar, Bookings, Tickets, and more! <= 7.4.2 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 04.08.202610.08.20267.3Events Manager <= 7.4.0 - Unauthenticated Privilege Escalation CVSS 7.3 · 10.08.20266.5Events Manager <= 7.4.0 - Authenticated (Subscriber+) SQL Injection CVSS 6.5 · 10.08.202624.08.20266.5Events Manager <= 7.4.0 - Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter in Event/Location Duplicate Action CVSS 6.5 · 24.08.20265.3Events Manager <= 7.4.0 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'status', 'private', and 'private_only' Parameters CVSS 5.3 · 24.08.20266.6Events Manager <= 7.3.7.4 - Authenticated (Administrator+) Local File Inclusion via 'dbem_data[updates]' Array Keys CVSS 6.6 · 24.08.20266.1Events Manager <= 7.4.0.1 - Reflected Cross-Site Scripting via 'header_format' Parameter CVSS 6.1 · 24.08.202604.09.20265.4Events Manager - Calendar, Bookings, Tickets, and more! <= 7.3.3 - Unauthenticated Stored Cross-Site Scripting via Event Attributes CVSS 5.4 · 04.09.2026

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

45

Get automatic notifications for all Events Manager – Calendar, Bookings, Tickets, and more! vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2015-9298

Events Manager <= 5.5.7.1 - Code Injection

Read the full analysis

Vulnerability Records

45 records
2026-09-04 00:00CVE-2025-14945
5.4
Medium
shark3yYes
2026-08-24 14:30CVE-2026-17089
6.1
Medium
Wordfence PRISMYes
2026-08-24 14:29CVE-2026-14280
6.6
Medium
Wordfence PRISMYes
2026-08-24 14:06CVE-2026-10627
5.3
Medium
molten bitYes
2026-08-24 13:24CVE-2026-15023
6.5
Medium
Dmitrii IgnatyevYes
2026-08-10 00:00CVE-2026-18366
7.3
High
Jakub HermanYes
2026-08-10 00:00CVE-2026-18057
6.5
Medium
Jakub HermanYes
2026-08-04 00:00CVE-2026-66457
7.2
High
Mukhlis AmienYes
2026-07-30 00:00CVE-2026-18050
5.3
Medium
Usama ArshadYes
2026-07-08 00:00CVE-2026-57713
8.1
High
dutafiYes
Showing 1–10 of 45 reports
Events Manager – Calendar, Bookings, Tickets, and more! banner
Latestv7.4.3

Events Manager – Calendar, Bookings, Tickets, and more!

Marcus (aka @msykes)

Author

Marcus (aka @msykes)

4.2(549)
84/100
Last Updated
2026-08-27 (17d ago)
Active Installs
60,000+
Downloads
6,412,788
Requires WP
6.1+
Requires PHP
7.0+
Tested up to
WP 7.0.4
Created
2008-08-06 (18y ago)

Events Manager is a full-featured event calendar, bookings, appointments, scheduling, and registration management plugin for WordPress ideal for everything from simple meetups to full-scale event planning. Built with flexibility, reliability and powerful features in mind. Demo Documentation Tutorials Main Features NEW Integrate easily with your favourite AI via MCP, unlock the power of AI-powered Events! NEW API Rest Integration NEW EU Compliance Tools for “Right of withdrawal” (EU &#8216;Widerrufsbutton’) Beautiful calendars, search pages, lists, grids and booking forms to enhance your site events. Easy event registration (single day with start/end times) Recurring and long (multi-day) event registration Build complex recurrence patterns with exclusion/blackout dates NEW Multiple timeslots within the day for events with advanced creation options Overlapping timeslots Buffer between timeslots Bookings Management (including approval/rejections, export CVS, and more!) Multiple Tickets Fully-featured graph and statistics including bar/line/pie with comparison and stacking MultiSite Event Support Cross-Network Event Sharing – show your events and booking fromss on other subsites or main site Network-wide Global Booking Management BuddyPress and BuddyBoss Support Create modular (independent) event subsites or inter-networked events Multiple custom event types (Archetypes), such as Workshops, Events, Webinars, Appointments etc. Customize your labels, slugs and CPT names Enable or disable specific features for specific event archetypes. Multiple Location Types Physical Locations Online Events (URLs) Zoom Webinars/Meetings Integration BuddyPress & BuddyBoss Support Submit Events Group Events Personal Events Activity Stream more on the way Guest/Member Event submissions Assign event locations and view events by location Event categories Easily create custom event attributes (e.g. dress code) Google Maps (see our API usage recommendations) Advanced permissions – restrict user management of events and locations. Widgets for Events, Locations and Calendars Fine grained control of how every aspect of your events are shown on your site, easily modify templates from the settings pages and template files iCal Feed (single and all events) Add to Google Calendar buttons RSS Feeds Compatible with SEO plugins Timezone Support – create events in different timezones Plenty of template tags and shortcodes for use in your posts and pages Gutenberg block editor support, with native blocks for the Events Calendar, Events List, and Locations List — usable in posts, pages, the site editor and the widget editor Actively maintained and supported Lots of documentation and tutorials NEW Gutenberg Supported And much more! AI Integration AI is here, and we’re on board! Check out what’s possible with our new and evolving AI integration possibilities: Data Privacy and GDPR Compliance We provide the tools to help you be GDPR compliant, including: export/erasure of data via the WordPress Privacy Tools, including booking, event and location data consent checkboxes on our booking, event and location forms on the frontend settings to control what can be exported/erased as well as where/when to place consent requests sample text for your site privacy policy describing what Events Manager does with personal data Premium Features We have a premium Pro add-on for Events Manager which not only demonstrates the flexibility of Events Manager, but also adds some important features including but not limited to: WooCommerce integration (sold separately) PayPal, Stripe, Authorize.net, Square, Xero and Offline Payments Custom booking forms Individual Attendee custom forms Upload fields for bookings, attendees and users Printable Invoices and Tickets Send PDF tickets/invoices by email automatically Check In/Out Move bookings to other dates/times QR Scanning Manage bookings on your phone Check In/Out users Waitlists Automation – ultimate flexibility in automation! Triggers: X time before/after events start When a booking status changes When a booking was booked x time ago Actions Send Webhook (Zapier, MS Automation and many other services) Send Email Send WhatsApp, SMS, Telegram notifications WhatsApp, SMS, Telegram integration and interactive flows Coupon Codes Custom booking email per event and gateway Faster support via private Pro forums For more information or to go pro, visit our plugin website. Additional Plugin Integrations Whilst there’s many third party integrations with our own plugin, here’s some we’ve integrated ourselves! Included in Events Manager (automatic integration) BuddyPress WP FullCalendar Thrive Automator Additional Add-Ons Zoom WPML Multilingual Sites

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C