cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forevent-post event-post

Direction: descending
Jul 29, 2026

Event post # CVE-2026-65486

CVE, Research URL

CVE-2026-65486

Application

Event post

Date
Jul 23, 2026
Research Description
Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
Affected versions
max 6.1.0.
Status
vulnerable
Jun 14, 2026

Event post # CVE-2025-49298

CVE, Research URL

CVE-2025-49298

Application

Event post

Date
Jun 06, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post event-post allows Stored XSS.This issue affects Event post: from n/a through <= 5.10.1.
Affected versions
max 5.10.2.
Status
vulnerable
Nov 10, 2025

Event post # CVE-2025-62042

CVE, Research URL

CVE-2025-62042

Application

Event post

Date
Oct 22, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post event-post.This issue affects Event post: from n/a through <= 5.10.3.
Affected versions
max 5.10.4.
Status
vulnerable
Apr 23, 2025

Event post # CVE-2025-46228

CVE, Research URL

CVE-2025-46228

Application

Event post

Date
Apr 22, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post event-post allows DOM-Based XSS.This issue affects Event post: from n/a through <= 5.9.11.
Affected versions
max 5.10.0.
Status
vulnerable
Mar 26, 2025

Event post # CVE-2025-2167

CVE, Research URL

CVE-2025-2167

Application

Event post

Date
Mar 26, 2025
Research Description
The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list' shortcodes in all versions up to, and including, 5.9.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 5.9.10.
Status
vulnerable
Mar 19, 2025

Event post # CVE-2025-26923

CVE, Research URL

CVE-2025-26923

Application

Event post

Date
Mar 26, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post event-post allows Stored XSS.This issue affects Event post: from n/a through <= 5.9.8.
Affected versions
max 5.9.9.
Status
vulnerable
Jan 26, 2025

Event post # CVE-2025-24585

CVE, Research URL

CVE-2025-24585

Application

Event post

Date
Jan 24, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post event-post allows Stored XSS.This issue affects Event post: from n/a through <= 5.9.7.
Affected versions
max 5.9.8.
Status
vulnerable
Nov 07, 2024

Event post # CVE-2024-10186

CVE, Research URL

CVE-2024-10186

Application

Event post

Date
Nov 06, 2024
Research Description
The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's events_cal shortcode in all versions up to, and including, 5.9.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 5.9.7.
Status
vulnerable
Jul 23, 2024

Event post # CVE-2024-38735

CVE, Research URL

CVE-2024-38735

Application

Event post

Date
Jul 12, 2024
Research Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Bastien Ho Event post event-post.This issue affects Event post: from n/a through <= 5.9.5.
Affected versions
max 5.9.6.
Status
vulnerable
Jul 13, 2024

Event post # CVE-2024-1375

CVE, Research URL

CVE-2024-1375

Application

Event post

Date
Jul 12, 2024
Research Description
The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing nonce check on the save_bulkdatas function in all versions up to, and including, 5.9.10. This makes it possible for unauthenticated attackers to update post_meta_data via a forged request, granted they can trick a logged-in user into performing an action such as clicking on a link.
Affected versions
max 5.9.10.
Status
vulnerable
Jun 07, 2024

Event post # CVE-2024-1376

CVE, Research URL

CVE-2024-1376

Application

Event post

Date
May 24, 2024
Research Description
The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing capability check on the save_bulkdatas function in all versions up to, and including, 5.9.4. This makes it possible for authenticated attackers, with subscriber access or higher, to update post_meta_data.
Affected versions
max 5.9.5.
Status
vulnerable

Event post # CVE-2023-49179

CVE, Research URL

CVE-2023-49179

Application

Event post

Date
Dec 15, 2023
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N.O.U.S. Open Useful and Simple Event post allows Stored XSS.This issue affects Event post: from n/a through 5.8.6.
Affected versions
max 5.9.1.
Status
vulnerable