CVE-2023-0144: Mage-People Event Manager And Tickets Selling For Woocommerce

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

The Event Manager and Tickets Selling Plugin for WooCommerce WordPress plugin before 3.8.0 does not validate and escape some of its post meta before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Affected products

  • Mage-People Event Manager And Tickets Selling For Woocommerce: before 3.8.0 (fixed in 3.8.0)

Published 2023-02-06. Last modified 2026-06-17.