Skip to main content

Vendor/product archive

imithemes / eventer CVEs

Beta · best-effort

9 CVEs tagged to imithemes / eventer1 Critical, 3 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2025-39482

Published May 16, 2025

Missing Authorization vulnerability in imithemes Eventer eventer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eventer: from n/a throu…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-39481

Published May 16, 2025

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in imithemes Eventer eventer allows Blind SQL Injection.This issue affects Event…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-0959

Published Mar 7, 2025

The Eventer - WordPress Event & Booking Manager Plugin plugin for WordPress is vulnerable to SQL Injection via the reg_id parameter in all versions up to, and including, 3.9.9.2 d…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-22635

Published Feb 23, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in imithemes Eventer eventer allows Reflected XSS.This issue affects Eventer: fr…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-11134

Published Feb 3, 2025

The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'eventer_export_bookings_csv' function in all versions up to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11133

Published Feb 3, 2025

The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_pdf_download_request' function in all versions up to…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11132

Published Feb 3, 2025

The Eventer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.9.9.4 due to insufficient input sanitization and o…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11135

Published Jan 28, 2025

The Eventer plugin for WordPress is vulnerable to SQL Injection via the 'event' parameter in the 'eventer_get_attendees' function in all versions up to, and including, 3.9.8 due t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10799

Published Jan 17, 2025

The Eventer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.9.7 via the eventer_woo_download_tickets() function. This makes it po…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1