Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
Events Made Easy - Cross-Site Scripting (XSS) (CVE-2026-28162)
Unauthenticated Cross Site Scripting (XSS) in Events Made Easy
CVE-2026-28162
Events Made Easy - Path Traversal (CVE-2026-75963)
The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The stored traversal payload is triggered passively…
CVE-2026-75963
Events Made Easy - Security Vulnerability (CVE-2026-14842)
The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauthenticated attackers to pay a low amount for a cheap booking and have a separate, higher-priced booking marked as fully paid.
CVE-2026-14842
Events Made Easy - Security Vulnerability (CVE-2026-14843)
The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated data-change request, relying only on a public nonce with no per-record token or ownership check, allowing unauthenticated attackers to overwrite the personal data of any person record.
CVE-2026-14843
Events Made Easy - Broken Access Control (CVE-2026-59557)
Unauthenticated Broken Access Control in Events Made Easy
CVE-2026-59557
Events Made Easy - Security Vulnerability (CVE-2023-28660)
The Events Made Easy WordPress Plugin, version
CVE-2023-28660
Events Made Easy - Broken Access Control (CVE-2023-0404)
The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions related to AJAX actions in versions up to, and including, 2.3.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke those functions intended for administrator use. While the plugin is still pending review from the WordPress repository, site owners can download a copy of the patched version directly from the developer's Github at https://github.com/liedekef/events-made-easy
CVE-2023-0404
Events Made Easy - SQL Injection (CVE-2022-1905)
The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
CVE-2022-1905
Events Made Easy - SQL Injection (CVE-2021-25030)
The Events Made Easy WordPress plugin before 2.2.36 does not sanitise and escape the search_text parameter before using it in a SQL statement via the eme_searchmail AJAX action, available to any authenticated users. As a result, users with a role as low as subscriber can call it and perform SQL injection attacks
CVE-2021-25030
Events Made Easy - Cross-Site Scripting (XSS) (CVE-2021-24813)
The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2021-24813