
EventPrime – Events Calendar, Bookings and Tickets Security & Risk Analysis
wordpress.org/plugins/eventprime-event-calendar-managementModern Events Calendar plugin ❤️ for creating free or paid events. Supports Event Types, Bookings, Tickets, Venues, Performers, and a lot more.
Is EventPrime – Events Calendar, Bookings and Tickets Safe to Use in 2026?
Generally Safe
Score 92/100EventPrime – Events Calendar, Bookings and Tickets has a strong security track record. Known vulnerabilities have been patched promptly.
The EventPrime Event Calendar Management plugin, version 4.3.0.1, exhibits a mixed security posture. While it demonstrates strong adherence to secure coding practices with a high percentage of SQL queries using prepared statements and properly escaped output, significant concerns arise from its attack surface and vulnerability history. The presence of four unprotected AJAX handlers represents a substantial risk, potentially allowing unauthenticated users to trigger sensitive operations. The taint analysis further highlights this by revealing four high-severity flows, indicating potential vulnerabilities where user-supplied data could be manipulated with malicious intent. The plugin's history of 36 known CVEs, particularly the high number of medium severity vulnerabilities and the recent (though future-dated) high severity issue, suggests a pattern of recurring security weaknesses that have required patching. Despite the absence of currently unpatched vulnerabilities and the presence of nonce and capability checks in many areas, the high number of unprotected entry points and the identified critical taint flows are critical security flaws that cannot be overlooked.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- Large history of CVEs
- Bundled outdated library (TCPDF v1.0.004)
EventPrime – Events Calendar, Bookings and Tickets Security Vulnerabilities
CVEs by Year
Severity Breakdown
36 total CVEs
EventPrime <= 4.2.8.3 - Unauthenticated Information Exposure
EventPrime <= 4.2.8.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Event Modification via 'event_id' Parameter
EventPrime <= 4.2.8.4 - Missing Authorization to Unauthenticated Image Upload via 'ep_upload_file_media' AJAX Endpoint
EventPrime <= 4.2.8.0 - Missing Authorization
EventPrime - Events Calendar, Bookings and Tickets <= 4.2.7.0 - Unauthenticated Sensitive Information Exposure via REST API
EventPrime – Events Calendar, Bookings and Tickets <= 4.2.0.0 - Missing Authorization to Authenticated (Subscriber+) Booking Note Creation
EventPrime <= 4.2.4.1 - Authenticated (Subscriber+) Information Exposure
EventPrime <= 4.2.4.1 - Missing Authorization
EventPrime – Events Calendar, Bookings and Tickets <= 4.0.7.3 - Missing Authorization to Authenticated (Subscriber+) Event Attendees Export
EventPrime – Events Calendar, Bookings and Tickets <= 4.0.7.3 - Unauthenticated Stored Cross-Site Scripting via Ticket Category and Ticket Type Name
EventPrime – Events Calendar, Bookings and Tickets <= 3.5.0 - Insecure Direct Object Reference to (Subscriber+) Arbitrary Booking Update
EventPrime – Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting via Transaction Log
EventPrime – Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting
EventPrime <= 4.0.4.5 - Open Redirect
EventPrime <= 4.0.4.3 - Missing Authorization to Unauthenticated Private or Password-Protected Events Disclosure
EventPrime <= 4.0.3.2 - Missing Authorization via calendar_event_create()
EventPrime <= 3.3.4 - Missing Authorization to Booking Price Maniputlation
EventPrime <= 3.3.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Missing Authorization to Arbitrary Post Overwrite
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Unauthenticated Booking Payment Bypass
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.3 - Unauthenticated Stored Cross-Site Scripting
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Event Export
EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Missing Authorization to Authenticated (Subscriber+) Attendee List Retrieval
EventPrime <= 3.3.9 - Improper Input Validation via save_event_booking
EventPrime <= 3.3.5 - Missing Authorization to Private Event Disclosure
EventPrime – Modern Events Calendar, Bookings and Tickets <= 3.3.2 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
EventPrime <= 3.3.2 - Improper Server-Side Checks to Booking Payment Bypass
EventPrime <= 3.1.5 - Reflected Cross-Site Scripting via 'event_id'
EventPrime < 3.2.0 - Reflected Cross-Site Scripting via keyword and ep_filter_date
EventPrime < 3.2.0 - Cross-Site Request Forgery
EventPrime < 3.2.0 - Reflected HTML Content Injection
EventPrime <= 3.0.5 - Reflected Cross-Site Scripting
EventPrime <= 2.8.6 - Sensitive Information Exposure
EventPrime <= 2.8.6 - Reflected Cross-Site Scripting
EventPrime – Events Calendar, Bookings and Tickets Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
EventPrime – Events Calendar, Bookings and Tickets Attack Surface
AJAX Handlers 4
REST API Routes 1
WordPress Hooks 158
Maintenance & Trust
EventPrime – Events Calendar, Bookings and Tickets Maintenance & Trust
Maintenance Signals
Community Trust
EventPrime – Events Calendar, Bookings and Tickets Alternatives
Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered)
wp-event-solution
Create and manage events with a flexible WordPress events calendar plugin. Add recurring events, RSVP, ticket booking, and WooCommerce ticket selling …
Quick Event Manager
quick-event-manager
Simple event manager. No messing about, just add events and a shortcode and the plugin does the rest for you.
Event Monster – Manager & Ticket Booking
event-monster
Event manager with calendar display, ticket booking, registration forms, and attendee tracking for all occasions.
My Calendar – Accessible Event Manager
my-calendar
Accessible WordPress event calendar plugin. Manage single or recurring events, event venues, and display your calendar anywhere on your site.
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce
wp-event-manager
Lightweight, scalable and full-featured event listings & management plugin for managing events & tickets from the Frontend and Backend.
EventPrime – Events Calendar, Bookings and Tickets Developer Profile
7 plugins · 79K total installs
How We Detect EventPrime – Events Calendar, Bookings and Tickets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.