Missing Authorization
20 records44.4%First: 2023. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 45 vulnerability records associated with EventPrime – Events Calendar, Bookings and Tickets, published between 2023 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2023 | 10 | |
| 2024 | 17 | |
| 2025 | 4 | |
| 2026 | 14 |
| Severity | Records | Share |
|---|---|---|
| High | 5 | 11.1% |
| Medium | 40 | 88.9% |
First: 2023. Latest: 2026.
First: 2023. Latest: 2026.
First: 2023. Latest: 2026.
First: 2023. Latest: 2026.
First: 2023. Latest: 2023.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
4.3.4.34.3.4.24.3.2.24.3.2.14.3.0.14.2.7.04.2.8.44.2.8.54.2.8.14.2.8.04.2.0.14.2.5.04.0.7.43.5.04.0.4.84.0.4.64.0.4.44.0.4.03.3.53.4.33.4.43.4.23.4.03.3.63.3.33.1.63.2.03.0.03.0.6Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-4.3.4.2 | EventPrime <= 4.3.4.2 - Unauthenticated Stored Cross-Site Scripting via 'new_event_type_background_color' Parameter | July 8, 2026 | 4.3.4.3 | High |
*-4.3.4.1 | EventPrime – Events Calendar, Bookings and Tickets <= 4.3.4.1 - Authenticated (Subscriber+) PHP Object Injection | June 25, 2026 | 4.3.4.2 | High |
*-4.3.2.1 | EventPrime – Events Calendar, Bookings and Tickets <= 4.3.2.1 - Unauthenticated PHP Object Injection | May 25, 2026 | 4.3.2.2 | High |
*-4.3.2.1 | EventPrime – Events Calendar, Bookings and Tickets <= 4.3.2.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting | May 24, 2026 | 4.3.2.2 | Medium |
*-4.3.2.0 | EventPrime – Events Calendar, Bookings and Tickets <= 4.3.2.0 - Missing Authorization | May 12, 2026 | 4.3.2.1 | Medium |
*-4.3.0.0 | EventPrime – Events Calendar, Bookings and Tickets <= 4.3.0.0 - Authenticated (Subscriber+) Insecure Direct Object Reference | April 20, 2026 | 4.3.0.1 | Medium |
*-4.2.8.3 | EventPrime – Events Calendar, Bookings and Tickets <= 4.2.8.3 - Missing Authorization | March 18, 2026 | 4.2.8.4 | Medium |
*-4.2.8.0 | EventPrime – Events Calendar, Bookings and Tickets <= 4.2.8.0 - Unauthenticated PHP Object Injection | March 17, 2026 | 4.2.8.1 | High |
*-4.2.6.0 | EventPrime – Events Calendar, Bookings and Tickets <= 4.2.6.0 - Missing Authorization | March 10, 2026 | 4.2.7.0 | Medium |
*-4.2.8.3 | EventPrime <= 4.2.8.3 - Unauthenticated Information Exposure | February 20, 2026 | 4.2.8.4 | Medium |
*-4.2.8.4 | EventPrime <= 4.2.8.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Event Modification via 'event_id' Parameter | February 17, 2026 | 4.2.8.5 | Medium |
*-4.2.8.4 | EventPrime <= 4.2.8.4 - Missing Authorization to Unauthenticated Image Upload via 'ep_upload_file_media' AJAX Endpoint | February 16, 2026 | 4.2.8.5 | Medium |
*-4.2.8.0 | EventPrime <= 4.2.8.0 - Missing Authorization | January 28, 2026 | 4.2.8.1 | Medium |
*-4.2.7.0 | EventPrime - Events Calendar, Bookings and Tickets <= 4.2.7.0 - Unauthenticated Sensitive Information Exposure via REST API | January 12, 2026 | 4.2.8.0 | Medium |
*-4.2.0.0 | EventPrime – Events Calendar, Bookings and Tickets <= 4.2.0.0 - Missing Authorization to Authenticated (Subscriber+) Booking Note Creation | November 7, 2025 | 4.2.0.1 | Medium |
*-4.2.4.1 | EventPrime <= 4.2.4.1 - Missing Authorization | November 6, 2025 | 4.2.5.0 | Medium |
*-4.2.4.1 | EventPrime <= 4.2.4.1 - Authenticated (Subscriber+) Information Exposure | November 6, 2025 | 4.2.5.0 | Medium |
*-4.0.7.3 | EventPrime – Events Calendar, Bookings and Tickets <= 4.0.7.3 - Missing Authorization to Authenticated (Subscriber+) Event Attendees Export | March 6, 2025 | 4.0.7.4 | Medium |
*-4.0.7.3 | EventPrime – Events Calendar, Bookings and Tickets <= 4.0.7.3 - Unauthenticated Stored Cross-Site Scripting via Ticket Category and Ticket Type Name | December 16, 2024 | 4.0.7.4 | High |
*-3.4.9 | EventPrime – Events Calendar, Bookings and Tickets <= 3.5.0 - Insecure Direct Object Reference to (Subscriber+) Arbitrary Booking Update | October 29, 2024 | 3.5.0 | Medium |
*-4.0.4.7 | EventPrime – Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting | October 23, 2024 | 4.0.4.8 | Medium |
*-4.0.4.7 | EventPrime – Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting via Transaction Log | October 23, 2024 | 4.0.4.8 | Medium |
*-4.0.4.5 | EventPrime <= 4.0.4.5 - Open Redirect | September 30, 2024 | 4.0.4.6 | Medium |
*-4.0.4.3 | EventPrime <= 4.0.4.3 - Missing Authorization to Unauthenticated Private or Password-Protected Events Disclosure | September 9, 2024 | 4.0.4.4 | Medium |
*-4.0.3.2 | EventPrime <= 4.0.3.2 - Missing Authorization via calendar_event_create() | August 9, 2024 | 4.0.4.0 | Medium |
Selected source records
Published: July 8, 2026
Published: June 25, 2026
Published: May 25, 2026
Published: May 24, 2026
Published: May 12, 2026
Published: April 20, 2026
Published: March 18, 2026
Published: March 17, 2026
Published: March 17, 2026
Published: May 25, 2026
Published: June 25, 2026
Published: July 8, 2026
Published: December 16, 2024
Published: March 8, 2024
Published: March 8, 2024
Published: May 24, 2026
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.