Stored Cross-Site Scripting Vulnerability in Events Manager Plugin for WordPress
CVE-2025-14945
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 September 2026
What is CVE-2025-14945?
The Events Manager plugin for WordPress is susceptible to Stored Cross-Site Scripting due to poor input sanitization of event attribute values. This flaw allows authenticated users with Author-level access or unauthenticated attackers (when anonymous event submissions are allowed) to inject malicious scripts. When other users view the affected event page, their browsers may execute these scripts, compromising user security and website integrity.
Affected Version(s)
Events Manager β Calendar, Bookings, Tickets, and more! 0 <= 7.3.3