Stored Cross-Site Scripting in WP Event Manager by a Major WordPress Vendor
CVE-2025-2800
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 July 2025
What is CVE-2025-2800?
The WP Event Manager plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) through the 'organizer_name' parameter. This vulnerability stems from inadequate input sanitization and output escaping. As a result, attackers without authentication can inject malicious scripts that execute when a user views affected pages, potentially leading to data theft or other harmful consequences.
Affected Version(s)
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce * <= 3.1.50