Missing Authorization
20 records44.4%First: 2023. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 45 vulnerability records associated with EventPrime – Events Calendar, Bookings and Tickets, published between 2023 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2023 | 10 | |
| 2024 | 17 | |
| 2025 | 4 | |
| 2026 | 14 |
| Severity | Records | Share |
|---|---|---|
| High | 5 | 11.1% |
| Medium | 40 | 88.9% |
First: 2023. Latest: 2026.
First: 2023. Latest: 2026.
First: 2023. Latest: 2026.
First: 2023. Latest: 2026.
First: 2023. Latest: 2023.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
4.3.4.34.3.4.24.3.2.24.3.2.14.3.0.14.2.7.04.2.8.44.2.8.54.2.8.14.2.8.04.2.0.14.2.5.04.0.7.43.5.04.0.4.84.0.4.64.0.4.44.0.4.03.3.53.4.33.4.43.4.23.4.03.3.63.3.33.1.63.2.03.0.03.0.6Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-3.3.4 | EventPrime <= 3.3.4 - Missing Authorization to Booking Price Maniputlation | April 5, 2024 | 3.3.5 | Medium |
*-3.3.9 | EventPrime <= 3.3.9 - Authenticated (Administrator+) Stored Cross-Site Scripting | March 25, 2024 | 3.4.0 | Medium |
*-3.4.3 | EventPrime – Events Calendar, Bookings and Tickets <= 3.4.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion | March 8, 2024 | 3.4.4 | Medium |
*-3.4.3 | EventPrime – Events Calendar, Bookings and Tickets <= 3.4.3 - Unauthenticated Stored Cross-Site Scripting | March 8, 2024 | 3.4.4 | Medium |
*-3.4.2 | EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Unauthenticated Booking Payment Bypass | March 8, 2024 | 3.4.3 | Medium |
*-3.4.2 | EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Missing Authorization to Arbitrary Post Overwrite | March 8, 2024 | 3.4.3 | Medium |
*-3.4.3 | EventPrime – Events Calendar, Bookings and Tickets <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending | March 8, 2024 | 3.4.4 | Medium |
*-3.4.2 | EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Missing Authorization to Authenticated (Subscriber+) Attendee List Retrieval | February 14, 2024 | 3.4.3 | Medium |
*-3.4.1 | EventPrime – Events Calendar, Bookings and Tickets <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Event Export | February 14, 2024 | 3.4.2 | Medium |
*-3.3.9 | EventPrime <= 3.3.9 - Improper Input Validation via save_event_booking | February 2, 2024 | 3.4.0 | Medium |
*-3.3.5 | EventPrime <= 3.3.5 - Missing Authorization to Private Event Disclosure | December 29, 2023 | 3.3.6 | Medium |
*-3.3.2 | EventPrime – Modern Events Calendar, Bookings and Tickets <= 3.3.2 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode | November 21, 2023 | 3.3.3 | Medium |
*-3.3.2 | EventPrime <= 3.3.2 - Improper Server-Side Checks to Booking Payment Bypass | October 30, 2023 | 3.3.3 | Medium |
*-3.1.5 | EventPrime <= 3.1.5 - Reflected Cross-Site Scripting via 'event_id' | October 11, 2023 | 3.1.6 | Medium |
[*, 3.2.0) | EventPrime < 3.2.0 - Reflected HTML Content Injection | October 9, 2023 | 3.2.0 | Medium |
[*, 3.2.0) | EventPrime < 3.2.0 - Cross-Site Request Forgery | October 9, 2023 | 3.2.0 | Medium |
[*, 3.2.0) | EventPrime < 3.2.0 - Reflected Cross-Site Scripting via keyword and ep_filter_date | October 9, 2023 | 3.2.0 | Medium |
*-2.8.6 | EventPrime <= 2.8.6 - Reflected Cross-Site Scripting | May 22, 2023 | 3.0.0 | Medium |
*-2.8.6 | EventPrime <= 2.8.6 - Sensitive Information Exposure | May 22, 2023 | 3.0.0 | Medium |
*-3.0.5 | EventPrime <= 3.0.5 - Reflected Cross-Site Scripting | May 22, 2023 | 3.0.6 | Medium |
Selected source records
Published: July 8, 2026
Published: June 25, 2026
Published: May 25, 2026
Published: May 24, 2026
Published: May 12, 2026
Published: April 20, 2026
Published: March 18, 2026
Published: March 17, 2026
Published: March 17, 2026
Published: May 25, 2026
Published: June 25, 2026
Published: July 8, 2026
Published: December 16, 2024
Published: March 8, 2024
Published: March 8, 2024
Published: May 24, 2026
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.