cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches formage-eventpress mage-eventpress

Direction: descending
Apr 12, 2025

Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin # CVE-2025-32145

CVE, Research URL

CVE-2025-32145

Date
Apr 10, 2025
Research Description
Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently allows Object Injection. This issue affects WpEvently: from n/a through 4.3.5.
Affected versions
Min -, max -.
Status
vulnerable
Apr 02, 2025

Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin # CVE-2025-30887

CVE, Research URL

CVE-2025-30887

Date
Mar 27, 2025
Research Description
Missing Authorization vulnerability in magepeopleteam WpEvently allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpEvently: from n/a through 4.2.9.
Affected versions
Min -, max -.
Status
vulnerable

Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin # CVE-2025-30895

CVE, Research URL

CVE-2025-30895

Date
Mar 27, 2025
Research Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in magepeopleteam WpEvently allows PHP Local File Inclusion. This issue affects WpEvently: from n/a through 4.2.9.
Affected versions
Min -, max -.
Status
vulnerable
Oct 25, 2024

Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin # CVE-2024-49703

CVE, Research URL

CVE-2024-49703

Date
Oct 24, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagePeople Team Event Manager for WooCommerce allows Stored XSS.This issue affects Event Manager for WooCommerce: from n/a through 4.2.5.
Affected versions
Min -, max -.
Status
vulnerable
Aug 12, 2024

Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin # CVE-2024-43138

CVE, Research URL

CVE-2024-43138

Date
Aug 13, 2024
Research Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MagePeople Team Event Manager for WooCommerce allows PHP Local File Inclusion.This issue affects Event Manager for WooCommerce: from n/a through 4.2.1.
Affected versions
Min -, max -.
Status
vulnerable
Jun 06, 2024

Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin # CVE-2024-32110

CVE, Research URL

CVE-2024-32110

Date
-
Research Description
Event Manager and Tickets Selling Plugin for WooCommerce &#8211; WpEvently &#8211; WordPress Plugin [mage-eventpress] < 4.1.3 CVE-2024-32110
Affected versions
Min -, max -.
Status
vulnerable

Event Manager and Tickets Selling Plugin for WooCommerce &#8211; WpEvently &#8211; WordPress Plugin # CVE-2022-47164

CVE, Research URL

CVE-2022-47164

Date
May 25, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.7.7 versions.
Affected versions
Min -, max -.
Status
vulnerable

Event Manager and Tickets Selling Plugin for WooCommerce &#8211; WpEvently &#8211; WordPress Plugin # CVE-2022-0478

CVE, Research URL

CVE-2022-0478

Date
Mar 14, 2022
Research Description
The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which could allow users with a role as low as contributor to perform SQL Injection attacks
Affected versions
Min -, max -.
Status
vulnerable

Event Manager and Tickets Selling Plugin for WooCommerce &#8211; WpEvently &#8211; WordPress Plugin # CVE-2023-0144

CVE, Research URL

CVE-2023-0144

Date
Feb 07, 2023
Research Description
The Event Manager and Tickets Selling Plugin for WooCommerce WordPress plugin before 3.8.0 does not validate and escape some of its post meta before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected versions
Min -, max -.
Status
vulnerable

Event Manager and Tickets Selling Plugin for WooCommerce &#8211; WpEvently &#8211; WordPress Plugin # CVE-2023-28422

CVE, Research URL

CVE-2023-28422

Date
Mar 23, 2023
Research Description
Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce <= 3.8.6. versions.
Affected versions
Min -, max -.
Status
vulnerable

Event Manager and Tickets Selling Plugin for WooCommerce &#8211; WpEvently &#8211; WordPress Plugin # CVE-2023-36383

CVE, Research URL

CVE-2023-36383

Date
Jul 18, 2023
Research Description
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.9.5 versions.
Affected versions
Min -, max -.
Status
vulnerable

Event Manager and Tickets Selling Plugin for WooCommerce &#8211; WpEvently &#8211; WordPress Plugin # CVE-2024-24796

CVE, Research URL

CVE-2024-24796

Date
Feb 12, 2024
Research Description
Deserialization of Untrusted Data vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin.This issue affects Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin: from n/a through 4.1.1.
Affected versions
Min -, max -.
Status
vulnerable