VendorsImithemeseventerany version
Vulnerabilities

Imithemes Eventer any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2025-39481
WordPress Eventer plugin < 3.11.4 - SQL Injection vulnerability
Published 2025-05-16 · Modified
9.8EPSS 0.005
CVE-2025-39482
WordPress Eventer plugin < 3.11.4 - Broken Access Control vulnerability
Published 2025-05-16 · Modified
8.8EPSS 0.005
CVE-2025-0959
Eventer - WordPress Event & Booking Manager Plugin <= 3.9.9.2 - Authenticated (Subscriber+) SQL Injection via reg_id
Published 2025-03-07 · Analyzed
8.8EPSS 0.004
CVE-2024-11135
Eventer <= 3.9.8 - Unauthenticated SQL Injection via eventer_get_attendees
Published 2025-01-28 · Analyzed
7.5EPSS 0.005
CVE-2025-22635
WordPress Eventer - WordPress Event & Booking Manager Plugin plugin < 3.9.9 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2025-02-23 · Modified
7.1EPSS 0.002
CVE-2024-10799
Eventer <= 3.9.7 - Authenticated (Subscriber+) Arbitrary File Read
Published 2025-01-17 · Analyzed
6.5EPSS 0.007
CVE-2024-11134
Eventer <= 3.9.9 - Missing Authorization to Authenticated (Subscriber+) Bookings Export
Published 2025-02-03 · Analyzed
6.5EPSS 0.003
CVE-2024-11132
Eventer <= 3.9.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Published 2025-02-03 · Modified
6.4EPSS 0.003
CVE-2024-11133
Eventer <= 3.9.9.5 - Missing Authorization to Unauthenticated Event Ticket Download
Published 2025-02-03 · Modified
5.3EPSS 0.003