PLUGIN SECURITY
Is Wp Event Solution safe?
Event calendar plugin for event registration, event tickets, bookings, RSVP, recurring and virtual events with WooCommerce and Zoom (AI-powered).
What this plugin does
- Slug:
wp-event-solution - Author: Arraytics
- 10000+ active installs
- 94/100 rating (397 reviews on wordpress.org)
- 877683 all-time downloads
- On WordPress.org since 2020-04-28
calendarevent calendarevent registrationEvent Ticketsevents
Maintenance status
- Latest known version: 4.1.20
- Last updated: 2026-08-20 9:30am GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
40 known CVEs on file for Wp Event Solution.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-13172 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.22 | Missing Authorization | Unknown | < 4.1.22 | 4.1.22 | 2026-08-26 | ⚠ update needed |
| CVE-2026-77694 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.19 | Missing Authorization | Unknown | < 4.1.19 | 4.1.19 | 2026-08-26 | ✓ fixed in latest |
| CVE-2026-13176 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.21 | Server-Side Request Forgery (SSRF) | Low 2.7 | < 4.1.21 | 4.1.21 | 2026-08-21 | ⚠ update needed |
| CVE-2026-13175 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.21 | Authorization Bypass Through User-Controlled Key | Unknown | < 4.1.21 | 4.1.21 | 2026-08-17 | ⚠ update needed |
| CVE-2026-13174 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.21 | Improper Access Control | Unknown | < 4.1.21 | 4.1.21 | 2026-08-17 | ⚠ update needed |
| CVE-2026-13173 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.21 | Missing Authorization | Unknown | < 4.1.21 | 4.1.21 | 2026-08-17 | ⚠ update needed |
| CVE-2026-13169 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.21 | Authorization Bypass Through User-Controlled Key | Unknown | < 4.1.21 | 4.1.21 | 2026-08-17 | ⚠ update needed |
| CVE-2026-28174 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.19 | Insertion of Sensitive Information Into Sent Data | Medium 6.5 | < 4.1.19 | 4.1.19 | 2026-08-13 | ✓ fixed in latest |
+ 38 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-28173 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.20 | Missing Authorization | High 7.1 | < 4.1.20 | 4.1.20 | 2026-08-13 | ✓ fixed in latest |
| CVE-2026-13177 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.20 | Authorization Bypass Through User-Controlled Key | Unknown | < 4.1.20 | 4.1.20 | 2026-08-12 | ✓ fixed in latest |
| CVE-2026-13168 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.20 | Exposure of Sensitive Information to an Unauthorized Actor | Unknown | < 4.1.20 | 4.1.20 | 2026-08-12 | ✓ fixed in latest |
| CVE-2026-13171 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.20 | Improper Access Control | Unknown | < 4.1.20 | 4.1.20 | 2026-08-10 | ✓ fixed in latest |
| CVE-2026-13170 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.20 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Unknown | < 4.1.20 | 4.1.20 | 2026-08-06 | ✓ fixed in latest |
| CVE-2026-66451 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.10 | Authentication Bypass Using an Alternate Path or Channel | Medium 6.5 | < 4.1.10 | 4.1.10 | 2026-08-05 | ✓ fixed in latest |
| CVE-2026-13178 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.16 | Authorization Bypass Through User-Controlled Key | Unknown | < 4.1.16 | 4.1.16 | 2026-07-30 | ✓ fixed in latest |
| CVE-2026-13039 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.16 | Missing Authorization | Medium 5.3 | < 4.1.16 | 4.1.16 | 2026-07-09 | ✓ fixed in latest |
| CVE-2026-12924 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.16 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 4.1.16 | 4.1.16 | 2026-07-09 | ✓ fixed in latest |
| CVE-2025-68045 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.13 | Missing Authorization | High 7.5 | < 4.1.13 | 4.1.13 | 2026-06-15 | ✓ fixed in latest |
| CVE-2026-40776 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.9 | Missing Authorization | High 7.5 | < 4.1.9 | 4.1.9 | 2026-04-29 | ✓ fixed in latest |
| CVE-2025-68047 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.4 | Deserialization of Untrusted Data | High 8.8 | < 4.1.4 | 4.1.4 | 2026-01-22 | ✓ fixed in latest |
| CVE-2025-14657 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.52 | Missing Authorization | High 7.2 | < 4.0.52 | 4.0.52 | 2026-01-08 | ✓ fixed in latest |
| CVE-2025-49869 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.32 | Deserialization of Untrusted Data | High 8.8 | < 4.0.32 | 4.0.32 | 2025-08-13 | ✓ fixed in latest |
| CVE-2025-49321 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.29 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 4.0.29 | 4.0.29 | 2025-06-23 | ✓ fixed in latest |
| CVE-2025-47445 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.27 | Relative Path Traversal | High 7.5 | < 4.0.27 | 4.0.27 | 2025-05-14 | ✓ fixed in latest |
| CVE-2025-47539 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.27 | Incorrect Privilege Assignment | Unknown | < 4.0.27 | 4.0.27 | 2025-05-07 | ✓ fixed in latest |
| CVE-2025-39584 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.26 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | High 7.5 | < 4.0.26 | 4.0.26 | 2025-04-16 | ✓ fixed in latest |
| CVE-2025-26964 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.21 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | High 7.5 | < 4.0.21 | 4.0.21 | 2025-02-23 | ✓ fixed in latest |
| CVE-2024-56213 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.9 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Medium 6.5 | < 4.0.9 | 4.0.9 | 2024-12-19 | ✓ fixed in latest |
| CVE-2024-7149 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.9 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 8.8 | < 4.0.9 | 4.0.9 | 2024-09-26 | ✓ fixed in latest |
| CVE-2024-39648 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 4.0.6 | 4.0.6 | 2024-08-01 | ✓ fixed in latest |
| CVE-2024-6033 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.5 | Missing Authorization | Medium 4.3 | < 4.0.5 | 4.0.5 | 2024-07-16 | ✓ fixed in latest |
| CVE-2024-37507 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 4.0.0 | 4.0.0 | 2024-07-04 | ✓ fixed in latest |
| CVE-2024-1122 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 3.3.51 | Missing Authorization | Medium 5.3 | < 3.3.51 | 3.3.51 | 2024-02-08 | ✓ fixed in latest |
| CVE-2023-49756 | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 3.3.53 | Missing Authorization | Medium 5.4 | < 3.3.53 | 3.3.53 | 2023-12-04 | ✓ fixed in latest |
| — | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.25 | Missing Authorization | Medium 5.3 | < 4.0.25 | 4.0.25 | 0000-00-00 | ✓ fixed in latest |
| — | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.25 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 8.8 | < 4.0.25 | 4.0.25 | 0000-00-00 | ✓ fixed in latest |
| — | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.27 | External Control of File Name or Path | High 7.5 | < 4.0.27 | 4.0.27 | 0000-00-00 | ✓ fixed in latest |
| — | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.35 | Authorization Bypass Through User-Controlled Key | High 8.8 | < 4.0.35 | 4.0.35 | 0000-00-00 | ✓ fixed in latest |
| — | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.9 | — | Unknown | < 4.1.9 | 4.1.9 | 0000-00-00 | ✓ fixed in latest |
| — | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.38 | — | High 7.2 | < 4.0.38 | 4.0.38 | 0000-00-00 | ✓ fixed in latest |
| CVE-2025-1770 | Event Manager, Events Calendar, Tickets, Registrations – Eventin < 4.0.25 - Authenticated (Contributor+) Local File Inclusion | — | Unknown | < 4.0.25 | 4.0.25 | — | ✓ fixed in latest |
| CVE-2025-1766 | Event Manager, Events Calendar, Tickets, Registrations – Eventin < 4.0.25 - Missing Authorization to Unauthenticated Payment Status Update | — | Unknown | < 4.0.25 | 4.0.25 | — | ✓ fixed in latest |
| CVE-2025-3419 | Event Manager, Events Calendar, Tickets, Registrations – Eventin < 4.0.27 - Unauthenticated Arbitrary File Read | — | Unknown | < 4.0.27 | 4.0.27 | — | ✓ fixed in latest |
| CVE-2025-4796 | Eventin < 4.0.35 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover | — | Unknown | < 4.0.35 | 4.0.35 | — | ✓ fixed in latest |
| CVE-2025-7813 | Event Manager, Events Calendar, Booking, Registrations and Tickets – Eventin < 4.0.38 - Unauthenticated Server-Side Request Forgery | — | Unknown | < 4.0.38 | 4.0.38 | — | ✓ fixed in latest |
| CVE-2026-4109 | Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) < 4.1.9 Missing Authorization to Authenticated (Subscriber+) Order Information Exposure | — | Unknown | < 4.1.9 | 4.1.9 | — | ✓ fixed in latest |
How to fix it
Keep Wp Event Solution updated — 4.1.20 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- The Events Calendar — 600000+ active installs — 84/100 (2450)
- Events Manager – Calendar, Bookings, Tickets, and more! — 60000+ active installs — 84/100 (547) — max PHP <8.0
- SimplyBook.me – Booking and reservations calendar — 30000+ active installs — 90/100 (17) — max PHP 8.4
- Timetable and Event Schedule by MotoPress — 30000+ active installs — 86/100 (69) — max PHP <8.0
- WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce — 20000+ active installs — 80/100 (247)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.