Events Manager – Calendar, Bookings, Tickets, and more! ikon

Events Manager – Calendar, Bookings, Tickets, and more!

4.2/5
70 000+ installationer

Events calendar with bookings, scheduling, appointments, event registration, tickets, recurring events, and venue management.

30
Kända sårbarheter
7
Kritiska / höga
2025-12-18
Senaste sårbarhet
70 000+
Aktiva installationer

Om Events Manager – Calendar, Bookings, Tickets, and more!

Events Manager är ett populärt WordPress-tillägg som används av cirka 70 000 webbplatser för att hantera evenemang, bokningar, biljetter och återkommande aktiviteter. Tillägget erbjuder omfattande funktionalitet för eventhantering, inklusive kalender, registreringar och platshantering.

Säkerhetsstatus

Tillägget har totalt 24 dokumenterade sårbarheter, vilket är betydligt fler än genomsnittet för WordPress-tillägg. Fördelningen visar 1 kritisk, 5 höga, 15 medelallvarliga och 3 låga sårbarheter. Särskilt oroande är att den senaste kända sårbarheten upptäcktes så sent som december 2025, vilket indikerar pågående säkerhetsproblem.

Rekommendationer

Företag som använder Events Manager bör vara extra uppmärksamma på säkerhetsuppdateringar. Den höga frekvensen av sårbarheter, kombinerat med tilläggets komplexa funktionalitet för användarinteraktion och datahantering, skapar en förhöjd riskprofil.

Vi rekommenderar att:

  • Alltid köra den senaste versionen av tillägget
  • Övervåka säkerhetsmeddelanden noggrant
  • Överväga alternativa eventhanteringslösningar om säkerheten är kritisk för verksamheten

Regelbundna uppdateringar är det mest effektiva skyddet mot kända säkerhetshot och bör prioriteras högt för alla som använder detta tillägg.

Använder du Events Manager – Calendar, Bookings, Tickets, and more!?

Kör ett gratis test och se om din hemsida är påverkad av dessa sårbarheter.

Testa din hemsida

Alla kända sårbarheter

Medel CVE-2025-12976

CVE-2025-12976: The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list_grouped' shortcode in all versions up t...

Påverkade versioner: all

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list_grouped' shortcode in all versions up to, and including, 7.2.2.1 due to insufficient input san...

Medel CVE-2025-12976

Events Manager <= 7.2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'events_list_grouped' Shortcode

Påverkade versioner: <= 7.2.2.1

Medel CVE-2025-12408

CVE-2025-12408: The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 7.2.2.2 via the 'get_location' action ...

Påverkade versioner: all

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 7.2.2.2 via the 'get_location' action due to insufficient restrictions on which locations can...

Medel CVE-2025-12407

CVE-2025-12407: The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.2.2. This is due to missing ...

Påverkade versioner: all

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.2.2. This is due to missing or incorrect nonce validation on the 'location_delete'...

Medel CVE-2025-12407

Events Manager – Calendar, Bookings, Tickets, and more! <= 7.2.2.2 - Cross-Site Request Forgery to Location Deletion

Påverkade versioner: <= 7.2.2.2

Medel CVE-2025-12408

Events Manager <= 7.2.2.2 - Unauthenticated Information Exposure

Påverkade versioner: <= 7.2.2.2

Medel CVE-2025-7663

CVE-2025-7663: The Ovatheme Events Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the /class-ovaem-ajax.php file in all versions up to,...

Påverkade versioner: all

The Ovatheme Events Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the /class-ovaem-ajax.php file in all versions up to, and including, 1.8.6. This makes it possible for una...

Kritisk CVE-2025-6553

CVE-2025-6553: The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_checkout() function in all versions up to, and including,...

Påverkade versioner: all

The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_checkout() function in all versions up to, and including, 1.8.5. This makes it possible for unauthenticated at...

Medel CVE-2025-6976

CVE-2025-6976: The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7....

Påverkade versioner: < 6.6.5

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output e...

Medel CVE-2025-6975

CVE-2025-6975: The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘calendar_header’ parameter in all versions up to, and...

Påverkade versioner: < 6.6.5

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘calendar_header’ parameter in all versions up to, and including, 7.0.3 due to insufficient input sanitization an...

Hög CVE-2025-6970

CVE-2025-6970: The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7....

Påverkade versioner: < 6.6.5

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied param...

Medel CVE-2025-6976

Events Manager <= 7.0.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes

Påverkade versioner: <= 6.6.4.4

Hög CVE-2025-6970

Events Manager <= 7.0.3 - Unauthenticated SQL Injection via `orderby` Parameter

Påverkade versioner: <= 6.6.4.4

Medel CVE-2025-6975

Event Manager <= 7.0.3 - Reflected Cross-Site Scripting via `calendar_header` Parameter

Påverkade versioner: <= 6.6.4.4

Hög CVE-2024-11260

CVE-2024-11260: The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6....

Påverkade versioner: < 6.6.4

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient escaping on the user supplied p...

Hög CVE-2024-7717

CVE-2024-7717: The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 2.1.11 due to insufficient escaping on the u...

Påverkade versioner: < 2.2.0

The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 2.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation...

Medel CVE-2024-5889

CVE-2024-5889: The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ parameter in all versions up to, and includi...

Påverkade versioner: < 6.4.9

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output...

Medel CVE-2024-3492

CVE-2024-3492: The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' shortcodes...

Påverkade versioner: < 6.4.8

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' shortcodes in all versions up to, and including, 6.4.7.3 due to i...

Medel CVE-2024-2111

CVE-2024-2111: The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the physical location value in all versions up to, and including,...

Påverkade versioner: < 6.4.7.2

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the physical location value in all versions up to, and including, 6.4.7.1 due to insufficient input sanitization and out...

Medel CVE-2024-2110

CVE-2024-2110: The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.7.1. This is due to missing ...

Påverkade versioner: < 6.4.7.2

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.7.1. This is due to missing or incorrect nonce validation on several actions. This...

Medel CVE-2024-0614

CVE-2024-0614: The Events Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.4.6.4 due to insufficient input sanitization and outp...

Påverkade versioner: < 6.4.7

The Events Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.4.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...

Hög CVE-2022-1194

CVE-2022-1194: The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to...

Påverkade versioner: < 1.4.8

The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability.

Medel CVE-2021-25049

CVE-2021-25049: The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unf...

Påverkade versioner: < 1.4.4

The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Medel CVE-2020-35037

CVE-2020-35037: The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues

Påverkade versioner: < 5.9.8

The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues

Hög CVE-2020-35012

CVE-2020-35012: The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection

Påverkade versioner: < 5.9.8

The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection

Medel CVE-2019-16523

CVE-2019-16523: The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortco...

Påverkade versioner: <= 5.9.5

The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and events_map) provided by the pl...

Låg CVE-2018-13137

CVE-2018-13137: The Events Manager plugin 5.9.4 for WordPress has XSS via the dbem_event_reapproved_email_body parameter to the wp-admin/edit.php?post_type=event&page=events-manager-options URI.

Påverkade versioner: all

The Events Manager plugin 5.9.4 for WordPress has XSS via the dbem_event_reapproved_email_body parameter to the wp-admin/edit.php?post_type=event&page=events-manager-options URI.

Låg CVE-2018-0576

CVE-2018-0576: Cross-site scripting vulnerability in Events Manager plugin prior to version 5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Påverkade versioner: < 5.9

Cross-site scripting vulnerability in Events Manager plugin prior to version 5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Låg CVE-2018-9020

CVE-2018-9020: The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature.

Påverkade versioner: < 5.8.1.2

The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature.

Medel CVE-2013-1407

CVE-2013-1407: Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9 for WordPress allow remote attackers to inject arbitrary web...

Påverkade versioner: <= 5.3.4

Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) scope parameter to index....

Så skyddar du din sajt

Sårbarheter i tillägg är den vanligaste attackytan för WordPress-sajter. Det bästa skyddet är att vara proaktiv — här är tre konkreta steg.

Håll tillägget uppdaterat

De flesta sårbarheter i Events Manager – Calendar, Bookings, Tickets, and more! åtgärdas snabbt av utvecklarna. Uppdatera alltid till senaste versionen.

Ta bort oanvända tillägg

Varje tillägg är en potentiell attackyta. Avinstallera det du inte aktivt använder.

Bevaka automatiskt

Med löpande övervakning upptäcker du problem innan de blir allvarliga.

Vill du slippa hålla koll själv? Med ett supportavtal från Sitesupport sköter vi uppdateringar och säkerhet åt dig.

Vanliga frågor om Events Manager – Calendar, Bookings, Tickets, and more!

Events Manager – Calendar, Bookings, Tickets, and more! har 30 kända sårbarheter, varav 7 med hög eller kritisk allvarlighetsgrad. Det betyder inte nödvändigtvis att tillägget är osäkert — de flesta sårbarheter åtgärdas i nya versioner. Det viktigaste är att alltid köra den senaste versionen.
Det enklaste sättet är att köra ett gratis test av din hemsida på sitesupport.co. Testet kontrollerar vilka tillägg du använder och vilka versioner som är installerade, och jämför det mot kända sårbarheter.
Uppdatera till den senaste versionen så snart som möjligt. Om det inte finns en uppdatering som åtgärdar problemet bör du överväga att tillfälligt inaktivera tillägget, särskilt om sårbarheten har kritisk eller hög allvarlighetsgrad.
Events Manager – Calendar, Bookings, Tickets, and more! har över 70 000 aktiva installationer på WordPress.org och ett betyg på 4.2 av 5. Populära tillägg har generellt bättre säkerhetsrutiner tack vare större community och fler ögon på koden.

Hur mår din hemsida?

Kör ett gratis test och se hur din sajt presterar inom SEO, säkerhet, prestanda och tillgänglighet — på under en minut.

Testa gratis

Inget konto krävs