VendorsMetagausseventprimeany version
Vulnerabilities

Metagauss EventPrime any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

27CVEs
CVE-2024-31275
WordPress EventPrime plugin <= 3.3.4 - Booking Price Manipulation vulnerability
Published 2024-06-09 · Modified
9.8EPSS 0.005
CVE-2024-43223
WordPress EventPrime plugin <= 4.0.3.2 - Broken Access Control vulnerability
Published 2024-11-01 · Analyzed
8.8EPSS 0.004
CVE-2024-24832
WordPress EventPrime plugin <= 3.3.9 - Broken Access Control vulnerability
Published 2024-03-23 · Modified
8.2EPSS 0.004
CVE-2024-12024
EventPrime – Events Calendar, Bookings and Tickets <= 4.0.7.3 - Unauthenticated Stored Cross-Site Scripting via Ticket Category and Ticket Type Name
Published 2024-12-17 · Modified
7.2EPSS 0.004
CVE-2023-45637
WordPress EventPrime Plugin <= 3.1.5 is vulnerable to Cross Site Scripting (XSS)
Published 2023-10-24 · Modified
7.1EPSS 0.004
CVE-2023-35884
WordPress EventPrime Plugin <= 3.0.5 is vulnerable to Cross Site Scripting (XSS)
Published 2023-06-20 · Modified
7.1EPSS 0.004
CVE-2023-33326
WordPress EventPrime Plugin <= 2.8.6 is vulnerable to Cross Site Scripting (XSS)
Published 2023-05-28 · Modified
7.1EPSS 0.004
CVE-2024-1123
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Missing Authorization to Arbitrary Post Overwrite
Published 2024-03-09 · Modified
6.5EPSS 0.004
CVE-2024-1320
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.3 - Unauthenticated Stored Cross-Site Scripting
Published 2024-03-09 · Modified
6.5EPSS 0.004
CVE-2024-4665
EventPrime – Events Calendar, Bookings and Tickets < 3.5.0 - Subscriber+ Arbitrary booking settings update
Published 2025-05-15 · Modified
6.4EPSS 0.003
CVE-2023-4250
EventPrime < 3.2.0 - Reflected XSS
Published 2023-10-31 · Modified
6.1EPSS 0.004
CVE-2023-5238
EventPrime < 3.2.0 - Reflected HTML Injection on keyword parameter
Published 2023-10-31 · Modified
6.1EPSS 0.004
CVE-2024-9865
EventPrime – Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting via Transaction Log
Published 2024-10-24 · Analyzed
6.1EPSS 0.004
CVE-2024-9864
EventPrime – Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting
Published 2024-10-24 · Analyzed
6.1EPSS 0.003
CVE-2024-29776
WordPress EventPrime plugin <= 3.3.9 - Cross Site Scripting (XSS) vulnerability
Published 2024-03-27 · Modified
5.9EPSS 0.004
CVE-2024-1125
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion
Published 2024-03-09 · Modified
5.4EPSS 0.003
CVE-2023-6447
EventPrime < 3.3.6 - Unauthenticated Event Access
Published 2024-01-22 · Modified
5.3EPSS 0.006
CVE-2023-4252
EventPrime <= 3.2.9 - Booking Pricing Bypass
Published 2023-11-27 · Modified
5.3EPSS 0.005
CVE-2023-33321
WordPress EventPrime plugin <= 2.8.6 - Sensitive Data Exposure
Published 2024-05-17 · Analyzed
5.3EPSS 0.005
CVE-2024-8369
EventPrime <= 4.0.4.3 - Missing Authorization to Unauthenticated Private or Password-Protected Events Disclosure
Published 2024-09-10 · Analyzed
5.3EPSS 0.003
CVE-2024-1321
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Unauthenticated Booking Payment Bypass
Published 2024-03-13 · Modified
5.3EPSS 0.003
CVE-2024-1127
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Event Export
Published 2024-03-13 · Modified
4.3EPSS 0.005
CVE-2024-1126
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Missing Authorization to Authenticated (Subscriber+) Attendee List Retrieval
Published 2024-03-13 · Modified
4.3EPSS 0.004
CVE-2024-1124
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending
Published 2024-03-09 · Modified
4.3EPSS 0.003
CVE-2024-13526
EventPrime – Events Calendar, Bookings and Tickets <= 4.0.7.3 - Missing Authorization to Authenticated (Subscriber+) Event Attendees Export
Published 2025-03-07 · Analyzed
4.3EPSS 0.003
CVE-2023-4251
EventPrime < 3.2.0 - Booking Creation via CSRF
Published 2023-10-31 · Modified
4.3EPSS 0.002
CVE-2023-5519
EventPrime < 3.2.0 - Booking Creation via CSRF
Published 2023-10-31 · Modified
4.3EPSS 0.002