CVE-2025-2799: WP Event Manager <= 3.1.49 - Authenticated (Administrator+) Stored Cross-Site Scripting
The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tag-name’ parameter in all versions up to, and including, 3.1.49 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfilteredhtml has been disabled.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2799?
CVE-2025-2799 has a medium severity due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-2799?
To fix CVE-2025-2799, update the WP Event Manager - Events Calendar, Registrations, Sell Tickets with WooCommerce plugin to version 3.1.50 or later.
What is the impact of CVE-2025-2799?
The impact of CVE-2025-2799 is that attackers can inject malicious scripts into the site via the 'tag-name' parameter.
Which versions are affected by CVE-2025-2799?
CVE-2025-2799 affects all versions of the WP Event Manager - Events Calendar, Registrations, Sell Tickets with WooCommerce plugin up to and including version 3.1.49.
Is there a patch for CVE-2025-2799?
Yes, a patch is available in version 3.1.50 of the WP Event Manager - Events Calendar, Registrations, Sell Tickets with WooCommerce plugin.