The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to generic SQL Injection via Stored 'meta_key' via Event/Location Duplicate Action in all versions up to, and including, 7.4.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is a second-order SQL injection: an attacker first plants SQL metacharacters in a custom meta key via the standard add-meta flow (WordPress stores these verbatim in wp_postmeta), then triggers the injection by invoking the event_duplicate or location_duplicate action, which reads the stored meta keys via get_post_meta() and concatenates them unsafely into the INSERT query.
We have discovered 24,735 live websites that are affected by CVE-2026-15023.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 24,735 live websites (70% of Events Manager for WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 106 versions ( 98% of all versions) |
| 6,305 websites | |
| 4,996 websites | |
| 1,964 websites | |
| 1,253 websites | |
| 1,227 websites | |
| 1,159 websites | |
| 696 websites | |
| 601 websites | |
| 562 websites | |
| 532 websites |
| .com | 6,095 websites |
| .de | 3,816 websites |
| .org | 3,302 websites |
| .nl | 1,166 websites |
| .fr | 985 websites |
| .it | 896 websites |
| .ch | 616 websites |
| .co.uk | 557 websites |
| .net | 510 websites |
| .at | 454 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **************.org | **,*** | ||
| ****.org | **,*** | ||
| *********.*******.org | **,*** | ||
| ********.org | **,*** | ||
| *****.br | **,*** | ||
| ****.org | **,*** | ||
| *****.org | **,*** | ||
| ***************.it | **,*** | ||
| ***********.*****.gov | **,*** | ||
| **********************.org | **,*** |
FAQ