Wp Events Manager

WordPress plugin · wp-events-manager · WordPress.org ↗
1
Critical
0
High
2
Known total
0
Unfixed
Running Wp Events Manager on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
CRITICAL
CVSS 9.8
WP Events Manager < 2.2.5 - Subscriber+ Payment Bypass via 'qty' Parameter
CVE.org
>=0, <2.2.5 v2.2.5 CVE-2026-14205 Aug 7, 2026
MEDIUM
CVSS 5.3
WP Events Manager < 2.2.5 - Unauthenticated Payment Bypass and Booking Status Update via IDOR
CVE.org
>=0, <2.2.5 v2.2.5 CVE-2026-15148 Aug 7, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.