← Back

E Dynamics

e-dynamics

5 CVEs • 1 product

Products (1)

Click to collapse
Toggle

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1E Dynamics
1Events Made Easy
Jun 17, 2026
Mar 22, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The Events Made Easy WordPress Plugin, version <= 2.3.14 is affected by an authenticated SQL injection vulnerability in the 'search_name' parameter in the eme_recurrences_list action.
1E Dynamics
1Events Made Easy
Jun 17, 2026
Jan 19, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions related to AJAX actions in versions up to, and including, 2.3.16. This makes it possi...Show more
The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions related to AJAX actions in versions up to, and including, 2.3.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke those functions intended for administrator use. While the plugin is still pending review from the WordPress repository, site owners can download a copy of the patched version directly from the developer's Github at https://github.com/liedekef/events-made-easyShow less
1E Dynamics
1Events Made Easy
Jun 17, 2026
Jun 20, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
1E Dynamics
1Events Made Easy
Jun 17, 2026
Jan 3, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Events Made Easy WordPress plugin before 2.2.36 does not sanitise and escape the search_text parameter before using it in a SQL statement via the eme_searchmail AJAX action, available to any authenticated users. As a...Show more
The Events Made Easy WordPress plugin before 2.2.36 does not sanitise and escape the search_text parameter before using it in a SQL statement via the eme_searchmail AJAX action, available to any authenticated users. As a result, users with a role as low as subscriber can call it and perform SQL injection attacksShow less
1E Dynamics
1Events Made Easy
Jun 17, 2026
Nov 1, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disal...Show more
The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less