Stored Cross-Site Scripting in WP Event Manager by a Major WordPress Vendor
CVE-2025-2800

7.2HIGH

What is CVE-2025-2800?

The WP Event Manager plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) through the 'organizer_name' parameter. This vulnerability stems from inadequate input sanitization and output escaping. As a result, attackers without authentication can inject malicious scripts that execute when a user views affected pages, potentially leading to data theft or other harmful consequences.

Affected Version(s)

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce * <= 3.1.50

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Ngoc Quang Bach
.