Metagauss Eventprime vulnerabilities
35 known vulnerabilities affecting metagauss/eventprime.
Total CVEs
35
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH4MEDIUM28UNKNOWN1
Vulnerabilities
Page 1 of 2
CVE-2026-24378CRITICALCVSS 9.8≥ n/a, ≤ <= 4.2.8.02026-03-25
CVE-2026-24378 [CRITICAL] CWE-502 CVE-2026-24378: Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-ma
Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affects EventPrime: from n/a through <= 4.2.8.0.
cvelistv5nvd
CVE-2025-69358HIGHCVSS 7.5≥ n/a, ≤ <= 4.2.6.02026-03-25
CVE-2025-69358 [HIGH] CWE-862 CVE-2025-69358: Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management all
Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <= 4.2.6.0.
cvelistv5nvd
CVE-2026-25312UNKNOWN≤ 4.2.8.32026-03-19
CVE-2026-25312 CWE-862 CVE-2026-25312: Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management all
Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <= 4.2.8.3.
cvelistv5nvd
CVE-2026-25389MEDIUMCVSS 5.3≤ 4.2.8.32026-02-19
CVE-2026-25389 [MEDIUM] CWE-497 CVE-2026-25389: Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Metagaus
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Retrieve Embedded Sensitive Data.This issue affects EventPrime: from n/a through <= 4.2.8.3.
cvelistv5nvd
CVE-2026-24380HIGHCVSS 8.8≤ 4.2.8.02026-01-22
CVE-2026-24380 [HIGH] CWE-862 CVE-2026-24380: Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management all
Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <= 4.2.8.0.
cvelistv5nvd
CVE-2025-63006MEDIUMCVSS 4.3≤ 4.2.4.12025-12-09
CVE-2025-63006 [MEDIUM] CWE-862 CVE-2025-63006: Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management all
Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <= 4.2.4.1.
cvelistv5nvd
CVE-2025-63007MEDIUMCVSS 4.3≤ 4.2.4.12025-12-09
CVE-2025-63007 [MEDIUM] CWE-201 CVE-2025-63007: Insertion of Sensitive Information Into Sent Data vulnerability in Metagauss EventPrime eventprime-e
Insertion of Sensitive Information Into Sent Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Retrieve Embedded Sensitive Data.This issue affects EventPrime: from n/a through <= 4.2.4.1.
cvelistv5nvd
CVE-2024-4665MEDIUMCVSS 6.4fixed in 3.5.02025-05-15
CVE-2024-4665 [MEDIUM] CWE-639 CVE-2024-4665: The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bo
The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce.
nvd
CVE-2024-13526MEDIUMCVSS 4.3fixed in 4.0.7.42025-03-07
CVE-2024-13526 [MEDIUM] CWE-862 CVE-2024-13526: The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unautho
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the export_submittion_attendees function in all versions up to, and including, 4.0.7.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to download
nvd
CVE-2024-12024MEDIUMCVSS 6.1fixed in 4.0.6.02024-12-17
CVE-2024-12024 [MEDIUM] CWE-79 CVE-2024-12024: The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the em_ticket_category_data and em_ticket_individual_data parameters in all versions up to, and including, 4.0.7.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers
nvd
CVE-2024-43223HIGHCVSS 8.8fixed in 4.0.4.02024-11-01
CVE-2024-43223 [HIGH] CWE-862 CVE-2024-43223: Missing Authorization vulnerability in EventPrime Events EventPrime allows Exploiting Incorrectly Co
Missing Authorization vulnerability in EventPrime Events EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 4.0.3.2.
nvd
CVE-2024-9864MEDIUMCVSS 6.1fixed in 4.0.4.82024-10-24
CVE-2024-9864 [MEDIUM] CWE-79 CVE-2024-9864: The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket names in all versions up to, and including, 4.0.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute
nvd
CVE-2024-9865MEDIUMCVSS 6.1fixed in 4.0.4.82024-10-24
CVE-2024-9865 [MEDIUM] CWE-79 CVE-2024-9865: The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ep_booking_attendee_fields’ fields in all versions up to, and including, 4.0.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts
nvd
CVE-2024-47648MEDIUMCVSS 6.1≤ 4.0.4.52024-10-10
CVE-2024-47648 [MEDIUM] CWE-601 CVE-2024-47648: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Metagauss EventPrime eventprime
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Metagauss EventPrime eventprime-event-calendar-management.This issue affects EventPrime: from n/a through <= 4.0.4.5.
cvelistv5nvd
CVE-2024-8369MEDIUMCVSS 5.3fixed in 4.0.4.42024-09-10
CVE-2024-8369 [MEDIUM] CWE-862 CVE-2024-8369: The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unautho
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected events due to missing authorization checks in all versions up to, and including, 4.0.4.3. This makes it possible for unauthenticated attackers to view private or password-protected events.
nvd
CVE-2024-31275CRITICALCVSS 9.8fixed in 3.3.5≥ n/a, ≤ 3.3.42024-06-09
CVE-2024-31275 [CRITICAL] CWE-862 CVE-2024-31275: Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a
Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.4.
cvelistv5nvd
CVE-2023-33321MEDIUMCVSS 5.3fixed in 3.0.0≥ n/a, ≤ 2.8.62024-05-17
CVE-2023-33321 [MEDIUM] CWE-862 CVE-2023-33321: Missing Authorization vulnerability in Metagauss EventPrime allows Exploiting Incorrectly Configured
Missing Authorization vulnerability in Metagauss EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 2.8.6.
cvelistv5nvd
CVE-2024-29776MEDIUMCVSS 4.8fixed in 3.4.0≥ n/a, ≤ 3.3.92024-03-27
CVE-2024-29776 [MEDIUM] CWE-79 CVE-2024-29776: Cross Site Scripting (XSS) vulnerability in Metagauss EventPrime.This issue affects EventPrime: from
Cross Site Scripting (XSS) vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.
cvelistv5nvd
CVE-2024-24832HIGHCVSS 7.5fixed in 3.4.0≥ n/a, ≤ 3.3.92024-03-23
CVE-2024-24832 [HIGH] CWE-862 CVE-2024-24832: Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a
Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.
cvelistv5nvd
CVE-2024-1321MEDIUMCVSS 5.3fixed in 3.4.32024-03-13
CVE-2024-1321 [MEDIUM] CWE-345 CVE-2024-1321: The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 3.4.2. This is due to the plugin allowing unauthenticated users to update the status of order payments. This makes it possible for unauthenticated attackers to book events for free.
nvd
1 / 2Next →