PLUGIN SECURITY

Is Events Manager safe?

Events calendar with bookings, scheduling, appointments, event registration, tickets, recurring events, and venue management.

What this plugin does

  • Slug: events-manager
  • Author: Marcus (aka @msykes)
  • 70000+ active installs
  • 84/100 rating (547 reviews on wordpress.org)
  • 6370528 all-time downloads
  • On WordPress.org since 2008-08-06

blockbookingscalendareventstickets

Maintenance status

  • Latest known version: 7.4.2
  • Last updated: 2026-08-07 1:23am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.0+
  • Max supported PHP (analyzed): <8.0

Known vulnerabilities

42 known CVEs on file for Events Manager.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15023 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] <= 7.4.0 (unfixed) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 6.5 < 7.4.1 7.4.1 2026-08-25 ✓ fixed in latest
CVE-2026-10627 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] <= 7.4.0 (unfixed) Missing Authorization Medium 5.3 < 7.4.1 7.4.1 2026-08-25 ✓ fixed in latest
CVE-2026-14280 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] <= 7.3.7.4 (unfixed) Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Medium 6.6 < 7.4 7.4 2026-08-25 ✓ fixed in latest
CVE-2026-17089 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] <= 7.4.0.1 (unfixed) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 7.4.1 7.4.1 2026-08-25 ✓ fixed in latest
CVE-2026-18366 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.4.1 Improper Privilege Management Unknown < 7.4.1 7.4.1 2026-08-10 ✓ fixed in latest
CVE-2026-18057 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.4.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Unknown < 7.4.1 7.4.1 2026-08-10 ✓ fixed in latest
CVE-2026-18050 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.4 Exposure of Sensitive Information to an Unauthorized Actor Unknown < 7.4 7.4 2026-08-06 ✓ fixed in latest
CVE-2026-57713 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.3.7 High 8.8 < 7.3.7 7.3.7 2026-07-08 ✓ fixed in latest
+ 49 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-66457 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] <= 7.4.2 (unfixed) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 7.4.2 7.4.2 2026-07-08 ✓ fixed in latest
CVE-2025-12976 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.2.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 7.2.3 7.2.3 2025-12-17 ✓ fixed in latest
CVE-2025-12407 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.2.2.3 Cross-Site Request Forgery (CSRF) Medium 4.3 < 7.2.2.3 7.2.2.3 2025-12-11 ✓ fixed in latest
CVE-2025-12408 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.2.2.3 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 7.2.2.3 7.2.2.3 2025-12-11 ✓ fixed in latest
CVE-2025-1249 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.6.4.2 Missing Authorization Medium 5.3 < 6.6.4.2 6.6.4.2 2025-02-26 ✓ fixed in latest
CVE-2024-11260 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.6.4 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 6.6.4 6.6.4 2025-02-20 ✓ fixed in latest
CVE-2024-5889 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 6.4.9 6.4.9 2024-06-28 ✓ fixed in latest
CVE-2024-3492 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 6.4.8 6.4.8 2024-06-11 ✓ fixed in latest
CVE-2024-30421 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.7.2 Cross-Site Request Forgery (CSRF) Medium 4.3 < 6.4.7.2 6.4.7.2 2024-03-28 ✓ fixed in latest
CVE-2024-30515 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.7 Missing Authorization High 8.8 < 6.4.7 6.4.7 2024-03-28 ✓ fixed in latest
CVE-2024-2110 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.7.2 Cross-Site Request Forgery (CSRF) Medium 4.3 < 6.4.7.2 6.4.7.2 2024-03-27 ✓ fixed in latest
CVE-2024-2111 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.7.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 6.4.7.2 6.4.7.2 2024-03-27 ✓ fixed in latest
CVE-2024-0614 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 6.4.7 6.4.7 2024-02-28 ✓ fixed in latest
CVE-2023-48326 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.4.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 6.4.6 6.4.6 2023-11-23 ✓ fixed in latest
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.8 Unknown < 5.9.8 5.9.8 2020-11-30 ✓ fixed in latest
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.8 Unknown < 5.9.8 5.9.8 2020-11-30 ✓ fixed in latest
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.8.2 Unknown < 5.9.8.2 5.9.8.2 2020-11-25 ✓ fixed in latest
CVE-2020-35012 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.8 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.2 < 5.9.8 5.9.8 2020-06-07 ✓ fixed in latest
CVE-2020-35037 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 5.9.8 5.9.8 2020-06-07 ✓ fixed in latest
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.7.2 Unknown < 5.9.7.2 5.9.7.2 2020-02-07 ✓ fixed in latest
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.7.2 Unknown < 5.9.7.2 5.9.7.2 2020-02-06 ✓ fixed in latest
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.7.2 Unknown < 5.9.7.2 5.9.7.2 2020-02-05 ✓ fixed in latest
CVE-2019-16523 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.9.6 5.9.6 2019-10-16 ✓ fixed in latest
CVE-2018-13137 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 5.9.5 5.9.5 2018-07-18 ✓ fixed in latest
CVE-2018-0576 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.9 5.9 2018-04-27 ✓ fixed in latest
CVE-2018-9020 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.8.1.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.8.1.2 5.8.1.2 2018-03-26 ✓ fixed in latest
CVE-2015-9298 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.6 Improper Control of Generation of Code ('Code Injection') Critical 9.8 < 5.6 5.6 2015-08-10 ✓ fixed in latest
CVE-2015-9297, CVE-2015-9298 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 5.6 5.6 2015-08-10 ✓ fixed in latest
CVE-2015-9299 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.5.7.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 5.5.7.1 5.5.7.1 2015-06-04 ✓ fixed in latest
CVE-2015-9300 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.5.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 5.5.7 5.5.7 2015-05-23 ✓ fixed in latest
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.5.2 Unknown < 5.5.2 5.5.2 2015-05-15 ✓ fixed in latest
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.3.9 Unknown < 5.3.9 5.3.9 2015-05-15 ✓ fixed in latest
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.3.6 Unknown < 5.3.6 5.3.6 2015-05-15 ✓ fixed in latest
CVE-2013-7477 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.5.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 5.5.2 5.5.2 2014-08-01 ✓ fixed in latest
CVE-2013-7479 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.3.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 5.3.9 5.3.9 2014-08-01 ✓ fixed in latest
CVE-2013-7478 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 5.5 5.5 2013-08-14 ✓ fixed in latest
CVE-2013-7480 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.3.6.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 5.3.6.1 5.3.6.1 2013-02-27 ✓ fixed in latest
CVE-2013-1407 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.3.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 5.3.5 5.3.5 2013-01-19 ✓ fixed in latest
CVE-2012-6716 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.1.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 5.1.7 5.1.7 2012-05-22 ✓ fixed in latest
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.6.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 6.6.5 6.6.5 0000-00-00 ✓ fixed in latest
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.6.5 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 6.6.5 6.6.5 0000-00-00 ✓ fixed in latest
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.6.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 6.6.5 6.6.5 0000-00-00 ✓ fixed in latest
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.3.7 Unknown < 7.3.7 7.3.7 0000-00-00 ✓ fixed in latest
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.7.2 Unknown < 5.9.7.2 5.9.7.2 ✓ fixed in latest
Events Manager < 5.9.7.2 - CSV Injection Unknown < 5.9.7.2 5.9.7.2 ✓ fixed in latest
CVE-2025-6970 Events Manager < 7.0.4 - Unauthenticated SQL Injection via `orderby` Parameter Unknown < 7.0.4 7.0.4 ✓ fixed in latest
CVE-2025-6975 Event Manager < 7.0.4 - Reflected Cross-Site Scripting via `calendar_header` Parameter Unknown < 7.0.4 7.0.4 ✓ fixed in latest
CVE-2025-6976 Events Manager < 7.0.4 - Authenticated(Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes Unknown < 7.0.4 7.0.4 ✓ fixed in latest
CVE-2026-12987 Events Manager < 7.3.7 - Unauthenticated SQL Injection via PHP Object Injection in Booking Registration Unknown < 7.3.7 7.3.7 ✓ fixed in latest

How to fix it

Keep Events Manager updated — 7.4.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.