Stored Cross-Site Scripting Vulnerability in Events Manager Plugin for WordPress
CVE-2025-14945

5.4MEDIUM

What is CVE-2025-14945?

The Events Manager plugin for WordPress is susceptible to Stored Cross-Site Scripting due to poor input sanitization of event attribute values. This flaw allows authenticated users with Author-level access or unauthenticated attackers (when anonymous event submissions are allowed) to inject malicious scripts. When other users view the affected event page, their browsers may execute these scripts, compromising user security and website integrity.

Affected Version(s)

Events Manager – Calendar, Bookings, Tickets, and more! 0 <= 7.3.3

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

shark3y
.