
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce Security & Risk Analysis
wordpress.org/plugins/wp-event-managerLightweight, scalable and full-featured event listings & management plugin for managing events & tickets from the Frontend and Backend.
Is WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce Safe to Use in 2026?
Generally Safe
Score 87/100WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
This plugin exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices with excellent output escaping (99%) and a high percentage of prepared SQL statements (78%). The significant number of nonce and capability checks (70 and 34 respectively) indicates an effort to secure various functionalities. However, there are notable areas of concern. The presence of two AJAX handlers without authentication checks presents a direct attack vector. The taint analysis revealing four flows with unsanitized paths, all rated as high severity, is particularly worrying, suggesting potential for serious vulnerabilities if not handled carefully. The plugin's history of 11 CVEs, including a critical and two high-severity vulnerabilities, with common types like RFI and XSS, is a significant red flag. Although no currently unpatched CVEs are listed, this history points to a recurring pattern of security weaknesses that require diligent patching and code review. In conclusion, while the plugin employs some good security measures, the combination of unauthenticated entry points, critical taint flows, and a history of serious vulnerabilities necessitates a cautious approach and prompt attention to identified risks.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized paths in taint analysis
- History of critical and high severity vulnerabilities
- History of RFI and XSS vulnerabilities
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
11 total CVEs
WP Event Manager <= 3.1.50 - Unauthenticated Stored Cross-Site Scripting via 'organizer_name'
WP Event Manager <= 3.1.49 - Authenticated (Administrator+) Stored Cross-Site Scripting
WP Event Manager <= 3.1.51 - Unauthenticated Local File Inclusion
WP Event Manager <= 3.2.0 - Missing Authorization
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce <= 3.1.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'events' Shortcode
WP Event Manager <= 3.1.41 - Reflected Cross-Site Scripting via plugin
WP Event Manager <= 3.1.41 - Authenticated (Editor+) Stored Cross-Site Scripting
WP Event Manager <= 3.1.42 - Cross-Site Scripting
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce <= 3.1.37.1 - Authenticated (Admin+) Stored Cross-Site Scripting
WP Event Manager – Easily Build your Calendar of Events! <= 3.1.27 - Stored Cross Site Scripting
WP Event Manager <= 3.1.22 - Admin+ Stored Cross-Site Scripting
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce Attack Surface
AJAX Handlers 12
Shortcodes 19
WordPress Hooks 150
Scheduled Events 3
Maintenance & Trust
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce Alternatives
The Events Calendar
the-events-calendar
The Events Calendar: #1 calendar plugin for WordPress. Create/manage events (virtual too!) on your site with the free plugin.
Events Manager – Calendar, Bookings, Tickets, and more!
events-manager
Events calendar with bookings, scheduling, appointments, event registration, tickets, recurring events, and venue management.
Event Organiser
event-organiser
Create and maintain events, including complex reoccurring patterns, venue management (with Google Maps or OpenStreetMap), calendars and customisable e …
Sugar Calendar – Events Calendar, Event Tickets, and Events Management Platform
sugar-calendar-lite
Easily manage events and sell tickets on your WordPress site. Sugar Calendar is easy-to-use, reliable, and exceptionally powerful. See for yourself.
Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered)
wp-event-solution
Create and manage events with a flexible WordPress events calendar plugin. Add recurring events, RSVP, ticket booking, and WooCommerce ticket selling …
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce Developer Profile
1 plugin · 20K total installs
How We Detect WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-event-manager/assets/css/frontend.css/wp-content/plugins/wp-event-manager/assets/css/prettyPhoto.css/wp-content/plugins/wp-event-manager/assets/css/select2.min.css/wp-content/plugins/wp-event-manager/assets/css/tooltipster.css/wp-content/plugins/wp-event-manager/assets/js/frontend.min.js/wp-content/plugins/wp-event-manager/assets/js/jquery-chosen/chosen.jquery.min.js/wp-content/plugins/wp-event-manager/assets/js/jquery-deserialize.min.js/wp-content/plugins/wp-event-manager/assets/js/jquery.livequery.min.js+30 more/wp-content/plugins/wp-event-manager/assets/js/frontend.min.js/wp-content/plugins/wp-event-manager/assets/js/jquery-chosen/chosen.jquery.min.js/wp-content/plugins/wp-event-manager/assets/js/jquery-deserialize.min.js/wp-content/plugins/wp-event-manager/assets/js/jquery.livequery.min.js/wp-content/plugins/wp-event-manager/assets/js/jquery.prettyPhoto.js/wp-content/plugins/wp-event-manager/assets/js/moment.min.js+12 more/wp-content/plugins/wp-event-manager/assets/css/frontend.css?ver=/wp-content/plugins/wp-event-manager/assets/css/prettyPhoto.css?ver=/wp-content/plugins/wp-event-manager/assets/css/select2.min.css?ver=/wp-content/plugins/wp-event-manager/assets/css/tooltipster.css?ver=/wp-content/plugins/wp-event-manager/assets/js/frontend.min.js?ver=/wp-content/plugins/wp-event-manager/assets/js/jquery-chosen/chosen.jquery.min.js?ver=/wp-content/plugins/wp-event-manager/assets/js/jquery-deserialize.min.js?ver=/wp-content/plugins/wp-event-manager/assets/js/jquery.livequery.min.js?ver=/wp-content/plugins/wp-event-manager/assets/js/jquery.prettyPhoto.js?ver=/wp-content/plugins/wp-event-manager/assets/js/moment.min.js?ver=/wp-content/plugins/wp-event-manager/assets/js/select2.full.min.js?ver=/wp-content/plugins/wp-event-manager/assets/js/tooltipster.bundle.min.js?ver=/wp-content/plugins/wp-event-manager/assets/js/wp-event-manager-frontend.min.js?ver=/wp-content/plugins/wp-event-manager/css/archive.css?ver=/wp-content/plugins/wp-event-manager/css/colorbox.css?ver=/wp-content/plugins/wp-event-manager/css/colorbox_mobile.css?ver=/wp-content/plugins/wp-event-manager/css/frontend.css?ver=/wp-content/plugins/wp-event-manager/css/frontend_dashboard.css?ver=/wp-content/plugins/wp-event-manager/css/frontend_submit.css?ver=/wp-content/plugins/wp-event-manager/css/frontend_submit_form.css?ver=/wp-content/plugins/wp-event-manager/css/listings.css?ver=/wp-content/plugins/wp-event-manager/css/map.css?ver=/wp-content/plugins/wp-event-manager/css/organizer-archive.css?ver=/wp-content/plugins/wp-event-manager/css/organizer-listings.css?ver=/wp-content/plugins/wp-event-manager/css/organizer-submit.css?ver=/wp-content/plugins/wp-event-manager/css/venue-archive.css?ver=/wp-content/plugins/wp-event-manager/css/venue-listings.css?ver=/wp-content/plugins/wp-event-manager/css/venue-submit.css?ver=/wp-content/plugins/wp-event-manager/js/frontend.min.js?ver=/wp-content/plugins/wp-event-manager/js/frontend-dashboard.min.js?ver=/wp-content/plugins/wp-event-manager/js/frontend-submit.min.js?ver=/wp-content/plugins/wp-event-manager/js/map.min.js?ver=/wp-content/plugins/wp-event-manager/js/wp-event-manager-ajax.min.js?ver=/wp-content/plugins/wp-event-manager/js/wp-event-manager-functions.min.js?ver=/wp-content/plugins/wp-event-manager/js/wp-event-manager-frontend.min.js?ver=/wp-content/plugins/wp-event-manager/js/wp-event-manager-shortcodes.min.js?ver=/wp-content/plugins/wp-event-manager/js/wp-event-manager-template.min.js?ver=HTML / DOM Fingerprints
wpem-backend-noticewpem-main-contentwpem-add-listing-noticewpem-dashboard-sidebarwpem-job-listing-detailwpem-job-listingswpem-listingswpem-organizer-listings+16 more<!-- Here are all the files for the admin side of WP Event Manager. --><!-- Here is the list of all the shortcodes for WP Event Manager. --><!-- Forms of WP Event manager. --><!-- In the case of third party support, use this. -->+11 moredata-event-manager-ajax-urldata-event-manager-templatedata-wp-event-manager-shortcodedata-event-iddata-event-urldata-organizer-id+13 moreWP_Event_Manager_AjaxWP_Event_Manager_Frontendevent_manager_paramsevent_manager_frontend_paramsevent_manager_frontend_dashboard_paramsevent_manager_frontend_submit_params+6 more/wp-json/wp-event-manager/v1/events/wp-json/wp-event-manager/v1/organizers/wp-json/wp-event-manager/v1/venues/wp-json/wp-event-manager/v1/categories/wp-json/wp-event-manager/v1/types/wp-json/wp-event-manager/v1/search/wp-json/wp-event-manager/v1/submit-event/wp-json/wp-event-manager/v1/submit-organizer/wp-json/wp-event-manager/v1/submit-venue/wp-json/wp-event-manager/v1/dashboard/events/wp-json/wp-event-manager/v1/dashboard/organizers/wp-json/wp-event-manager/v1/dashboard/venues/wp-json/wp-event-manager/v1/admin/settings[events][submit_event_form][event_dashboard][organizer_dashboard]