Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium2
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2026-04-15

CVE-2026-1655 - EventPrime – Events Calendar, Bookings and Tickets Plugin

The EventPrime plugin for WordPress is vulnerable to unauthorized post modification due to missing authorization checks in all versions up to, and including, 4.2.8.4. This is due to the save_frontend_event_submission function accepting a user-controlled event_id parameter and updating the corresponding event post without enforcing ownership or capability checks. This makes it possible for authenticated (Customer+) attackers to modify posts created by administrators by manipulating the event_id parameter granted they can obtain a valid nonce.

PLUGIN EventPrime – Events Calendar, Bookings and Tickets

CVE-2026-1655

MEDIUM CVSS 4.3 2026-02-18
Threat Entry Updated 2026-04-15

CVE-2026-1657 - EventPrime – Events Calendar, Bookings and Tickets Plugin

The EventPrime plugin for WordPress is vulnerable to unauthorized image file upload in all versions up to, and including, 4.2.8.4. This is due to the plugin registering the upload_file_media AJAX action as publicly accessible (nopriv-enabled) without implementing any authentication, authorization, or nonce verification despite a nonce being created. This makes it possible for unauthenticated attackers to upload image files to the WordPress uploads directory and create Media Library attachments via the ep_upload_file_media endpoint.

PLUGIN EventPrime – Events Calendar, Bookings and Tickets

CVE-2026-1657

MEDIUM CVSS 5.3 2026-02-17
Scroll to top