WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Event Espresso – Event Registration & Ticketing Sales

The best events plugin with event registration, free and paid ticket sales, event registration forms, PayPal payments, automatic emails, and more!

5Reported vulnerabilities
6.5Highest CVSS score
5.0.58.decafLatest version
600+Active installs

What to do now

Update Event Espresso – Event Registration & Ticketing Sales to 5.0.53.decaf or later. 5 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 17, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2025-68007 Medium 6.5 0.4% 5.0.37.decaf and earlier 5.0.53.decaf January 15, 2026
CVE-2023-27437 Medium 5.3 0.3% 4.10.44.decaf and earlier 4.10.45.decaf March 5, 2023
CVE-2024-56251 Medium 4.3 0.2% 5.0.28.decaf and earlier 5.0.31.decaf December 30, 2024
CVE-2024-6883 Medium 4.3 0.3% 0 to 4.10.46.decaf (inclusive) 5.0.22.decaf August 21, 2024
CVE-2021-4404 Medium 4.3 0.4% 4.10.11 and earlier 4.10.12 July 1, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.