Known Vulnerabilities for Event Espresso by Eventespresso
Listed below are 4 of the newest known vulnerabilities associated with "Event Espresso" by "Eventespresso".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-68007 json | Missing Authorization vulnerability in Event Espresso Event Espresso 4 Decaf event-espresso-decaf allows Exploiting Incorrect... | Not Provided | 2026-01-22 | 2026-04-23 |
| CVE-2025-32507 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aakif Kadiwala Event Es... | Not Provided | 2025-04-17 | 2026-04-23 |
| CVE-2024-56251 json | Cross-Site Request Forgery (CSRF) vulnerability in Event Espresso Event Espresso 4 Decaf event-espresso-decaf allows Cross Si... | Not Provided | 2025-01-02 | 2026-04-23 |
| CVE-2024-6883 json | The Event Espresso 4 Decaf – Event Registration Event Ticketing plugin for WordPress is vulnerable to limited unauthorized ... | Not Provided | 2024-08-21 | 2026-04-08 |
| CVE-2021-4404 json | The Event Espresso 4 Decaf plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,... | Not Provided | 2023-07-01 | 2026-04-08 |
| CVE-2021-4342 json | ** REJECT ** CVE split into individual CVE IDs for each software record. | Not Provided | 2023-06-07 | 2023-11-07 |
| CVE-2020-26153 json | A cross-site scripting (XSS) vulnerability in wp-content/plugins/event-espresso-core-reg/admin_pages/messages/templates/ee_ms... | 6.1 - MEDIUM | 2021-07-13 | 2021-07-15 |
| CVE-2017-1002026 json | Vulnerability in wordpress plugin Event Expresso Free v3.1.37.11.L, The function edit_event_category does not sanitize user-s... | 8.8 - HIGH | 2017-09-14 | 2019-07-31 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Eventespresso | Event Espresso | 4.9.82 | |||
| Application | Eventespresso | Event Espresso | 4.9.81 | |||
| Application | Eventespresso | Event Espresso | 4.9.80 | |||
| Application | Eventespresso | Event Espresso | 4.9.79 | |||
| Application | Eventespresso | Event Espresso | 4.9.78 | |||
| Application | Eventespresso | Event Espresso | 4.9.77 | |||
| Application | Eventespresso | Event Espresso | 4.9.76 | |||
| Application | Eventespresso | Event Espresso | 3.1.37.9 | |||
| Application | Eventespresso | Event Espresso | 3.1.37.8 | |||
| Application | Eventespresso | Event Espresso | 3.1.37.7 | |||
| Application | Eventespresso | Event Espresso | 3.1.37.6 | |||
| Application | Eventespresso | Event Espresso | 3.1.37.5 | |||
| Application | Eventespresso | Event Espresso | 3.1.37.4 | |||
| Application | Eventespresso | Event Espresso | 3.1.37.3 | |||
| Application | Eventespresso | Event Espresso | 3.1.37.2 | |||
| Application | Eventespresso | Event Espresso | 3.1.37.11.l | |||
| Application | Eventespresso | Event Espresso | 3.1.37.11 | |||
| Application | Eventespresso | Event Espresso | 3.1.37.10 | |||
| Application | Eventespresso | Event Espresso | 3.1.37.1 | |||
| Application | Eventespresso | Event Espresso | 3.1.37.0 |