WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Events Addon For Elementor safe?

Known vulnerabilities, PHP compatibility and safer alternatives for the Events Addon For Elementor WordPress plugin — checked against WP Clinic's local security database.

What this plugin does

  • Slug: events-addon-for-elementor
  • 7000+ active installs

addonsConferenceelementorelementor widgetevents

Maintenance status

  • Requires PHP: 7.4+

Known vulnerabilities

7 known CVEs on file for Events Addon For Elementor.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13362 Events Addon for Elementor [events-addon-for-elementor] < 2.2.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.2.5 2.2.5 2026-04-30
CVE-2024-12061 Events Addon for Elementor [events-addon-for-elementor] < 2.2.4 Authorization Bypass Through User-Controlled Key Medium 4.3 < 2.2.4 2.2.4 2024-12-17
CVE-2024-54315 Events Addon for Elementor [events-addon-for-elementor] < 2.2.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.2.3 2.2.3 2024-12-11
CVE-2024-49264 Events Addon for Elementor [events-addon-for-elementor] < 2.2.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.2.1 2.2.1 2024-10-14
CVE-2024-4669 Events Addon for Elementor [events-addon-for-elementor] < 2.1.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.1.7 2.1.7 2024-06-11
CVE-2023-47827 Events Addon for Elementor [events-addon-for-elementor] < 2.1.3 Incorrect Authorization Medium 6.5 < 2.1.3 2.1.3 2023-11-16
Events Addon for Elementor [events-addon-for-elementor] < 2.1.3 Unknown < 2.1.3 2.1.3 2023-11-14
Events Addon for Elementor [events-addon-for-elementor] < 2.1.3 Unknown < 2.1.3 2.1.3 2023-11-14

CVE-2024-13362

Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Source: CVE.org

CVE-2024-12061

The Events Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.3 via the naevents_elementor_template shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created by Elementor that they should not have access to.

Source: CVE.org

CVE-2024-54315

The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2024-49264

The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2024-4669

The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Basic Slider, Upcoming Events, and Schedule widgets in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2023-47827

The Events Addon for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the naevents_bw_settings_save_func(), naevents_bw_toggle_submit_func(), naevents_pro_settings_save_func(), naevents_pro_toggle_submit_func() and naevents_uw_settings_save_func() functions all hooked via nopriv AJAX actions in all versions up to, and including, 2.1.2. This makes it possible for unauthenticated attackers to modify the plugin's settings.

Source: WPScan

Events Addon for Elementor [events-addon-for-elementor] < 2.1.3

The Events Addon for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the naevents_bw_settings_save_func(), naevents_bw_toggle_submit_func(), naevents_pro_settings_save_func(), naevents_pro_toggle_submit_func() and naevents_uw_settings_save_func() functions all hooked via nopriv AJAX actions in all versions up to, and including, 2.1.2. This makes it possible for unauthenticated attackers to modify the plugin's settings.

Source: Wordfence

Events Addon for Elementor [events-addon-for-elementor] < 2.1.3

The Events Addon for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.2. This is due to missing nonce validation on the naevents_bw_settings_save_func(), naevents_bw_toggle_submit_func(), naevents_pro_settings_save_func(), naevents_pro_toggle_submit_func() and naevents_uw_settings_save_func() functions. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Source: Wordfence

+ 6 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-33999 Events Addon for Elementor [events-addon-for-elementor] < 2.0.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 2.0.3 2.0.3 2023-07-18
Events Addon for Elementor [events-addon-for-elementor] < 1.9.8 Missing Authorization Medium 6.3 < 1.9.8 1.9.8 2022-03-04
Events Addon for Elementor [events-addon-for-elementor] < 1.9.8 Unknown < 1.9.8 1.9.8 2022-02-28
Events Addon for Elementor [events-addon-for-elementor] < 1.9.8 Unknown < 1.9.8 1.9.8 2022-02-28
Events Addon for Elementor [events-addon-for-elementor] < 2.3.0 Medium 6.4 < 2.3.0 2.3.0 0000-00-00
Events Addon for Elementor [events-addon-for-elementor] < 2.1.3 Unknown < 2.1.3 2.1.3

CVE-2023-33999

Update the plugin to the latest version. Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Events Addon for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 2.0.3.

Source: Patchstack

Events Addon for Elementor [events-addon-for-elementor] < 1.9.8

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.

Source: Wordfence

Events Addon for Elementor [events-addon-for-elementor] < 1.9.8

Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Events Addon for Elementor plugin (versions < 1.9.8).

Source: Patchstack

Events Addon for Elementor [events-addon-for-elementor] < 1.9.8

Sensitive Information Disclosure vulnerability discovered in WordPress Events Addon for Elementor plugin (versions < 1.9.8).

Source: Patchstack

Events Addon for Elementor [events-addon-for-elementor] < 2.3.0

The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typewriter and Countdown widgets in all versions up to, and including, 2.2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

Events Addon for Elementor [events-addon-for-elementor] < 2.1.3

The plugin is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.2. This is due to missing nonce validation on the naevents_bw_settings_save_func(), naevents_bw_toggle_submit_func(), naevents_pro_settings_save_func(), naevents_pro_toggle_submit_func() and naevents_uw_settings_save_func() functions. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Source: WPScan

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.