WP Vulnerability WatchVulnerability data as of September 7, 2026

Vulnerability alerts / September 5, 2026

Vulnerability in Events Manager – Calendar, Bookings, Tickets, and more! — CVE-2025-14945

MediumSeverity
CVSS 5.4
0.2%Estimated exploit probability
EPSS
70,000+ sitesInstalls
7.3.4Fixed in

What to do now

Update Events Manager – Calendar, Bookings, Tickets, and more! to 7.3.4 or later.

Affected versions

  • Everything up to and including 7.3.3

Affected: Events Manager – Calendar, Bookings, Tickets, and more! (plugin, events-manager)

Check: The plugin on wordpress.org / Our record for Events Manager – Calendar, Bookings, Tickets, and more!

What the vulnerability is

The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event attribute values in all versions up to, and including, 7.3.3. This is due to insufficient input sanitization when storing attribute values (using only `wp_unslash()` without sanitization) and lack of output escaping when rendering the '#_ATT{key}' placeholder. This makes it possible for authenticated attackers, with Author-level access and above, or unauthenticated attackers when anonymous event submissions are enabled, to inject arbitrary web scripts that execute when any user views the affected event page.

This description is reproduced verbatim from the public vulnerability record.

Sources

See other alerts