CVEs we hold for Magepeople
Records whose assigning authority named Magepeople as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-85303WordPress Booking and Rental Manager plugin <= 2.7.7 - Cross Site Scripting (XSS) vulnerabilityMagepeople inc. Booking and Rental Manager
CVE-2026-81802WordPress WpEvently plugin <= 5.6.0 - Insecure Direct Object References (IDOR) vulnerabilityMagepeople inc. WpEvently
CVE-2026-81762WordPress Booking and Rental Manager plugin <= 2.7.6 - Broken Access Control vulnerabilitymagepeopleteam Booking and Rental Manager
CVE-2026-81761WordPress WpEvently plugin <= 5.5.0 - Broken Access Control vulnerabilityMagepeople inc. WpEvently
CVE-2026-81759WordPress WpEvently plugin <= 5.5.0 - Broken Access Control vulnerabilityMagepeople inc. WpEvently
CVE-2026-78258WordPress Booking and Rental Manager plugin <= 2.7.5 - Broken Access Control vulnerabilityMagepeople inc. Booking and Rental Manager
CVE-2026-78257WordPress Booking and Rental Manager plugin <= 2.7.5 - PHP Object Injection vulnerabilitymagepeopleteam Booking and Rental Manager
CVE-2026-73363WordPress Taxi Booking Manager for WooCommerce plugin < 2.0.8 - Broken Access Control vulnerabilitymagepeopleteam Taxi Booking Manager for WooCommerce
CVE-2026-66687WordPress WpBookingly plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerabilitymagepeopleteam WpBookingly
CVE-2026-61985WordPress Car Rental Manager plugin <= 1.3.7 - Broken Access Control vulnerabilitymagepeopleteam Car Rental Manager
CVE-2026-59532WordPress Booking and Rental Manager plugin <= 2.7.2 - Price Manipulation vulnerabilitymagepeopleteam Booking and Rental Manager
CVE-2026-57660WordPress Booking and Rental Manager plugin <= 2.7.1 - Broken Access Control vulnerabilitymagepeopleteam Booking and Rental Manager
CVE-2026-57404WordPress Booking and Rental Manager plugin <= 2.6.9 - Broken Access Control vulnerabilitymagepeopleteam Booking and Rental Manager
CVE-2026-45441WordPress WpEvently plugin <= 5.3.3 - Other Vulnerability Type vulnerabilityMagepeople inc. WpEvently
CVE-2026-39572WordPress Bus Ticket Booking with Seat Reservation plugin < 5.6.5 - Sensitive Data Exposure vulnerabilitymagepeopleteam Bus Ticket Booking with Seat Reservation
CVE-2026-39565WordPress WpTravelly plugin <= 2.1.7 - Broken Access Control vulnerabilitymagepeopleteam WpTravelly
CVE-2026-32384WordPress WpBookingly plugin <= 1.2.9 - Local File Inclusion vulnerabilitymagepeopleteam WpBookingly
CVE-2026-32354WordPress WpEvently plugin < 5.1.9 - Sensitive Data Exposure vulnerabilitymagepeopleteam WpEvently
CVE-2026-28040WordPress Taxi Booking Manager for WooCommerce plugin <= 2.0.0 - Cross Site Scripting (XSS) vulnerabilityMagepeople inc. Taxi Booking Manager for WooCommerce
CVE-2026-27405WordPress WpBookingly plugin <= 1.2.9 - Broken Access Control vulnerabilityMagepeople inc. WpBookingly
CVE-2026-27380WordPress Car Rental Manager plugin <= 1.3.9 - PHP Object Injection vulnerabilitymagepeopleteam Car Rental Manager
CVE-2026-27378WordPress Deposits and Partial Payments for WooCommerce plugin <= 3.1.0 - Broken Access Control vulnerabilitymagepeopleteam Deposits and Partial Payments for WooCommerce
CVE-2026-27345WordPress Taxi Booking Manager for WooCommerce plugin <= 2.0.3 - Broken Access Control vulnerabilitymagepeopleteam Taxi Booking Manager for WooCommerce
CVE-2026-27331WordPress WpTravelly plugin <= 2.1.5 - Broken Access Control vulnerabilityMagepeople inc. WpTravelly
CVE-2026-27095WordPress Bus Ticket Booking with Seat Reservation plugin <= 5.6.0 - PHP Object Injection vulnerabilitymagepeopleteam Bus Ticket Booking with Seat Reservation
CVE-2026-27089WordPress WpTravelly plugin <= 2.1.7 - Bypass Vulnerability vulnerabilityMagepeople inc. WpTravelly
CVE-2026-25444WordPress WpBookingly plugin <= 1.2.9 - Broken Access Control vulnerabilityMagepeople inc. WpBookingly
CVE-2026-25426WordPress Taxi Booking Manager for WooCommerce plugin <= 2.0.1 - Broken Access Control vulnerabilityMagepeople inc. Taxi Booking Manager for WooCommerce
CVE-2026-25361WordPress WpEvently plugin <= 5.1.4 - Reflected Cross Site Scripting (XSS) vulnerabilitymagepeopleteam WpEvently
CVE-2026-24954WordPress WpEvently plugin <= 5.0.8 - Deserialization of untrusted data vulnerabilitymagepeopleteam WpEvently
CVE-2026-24942WordPress WpEvently plugin <= 5.1.1 - Cross Site Request Forgery (CSRF) vulnerabilitymagepeopleteam WpEvently
CVE-2026-23972WordPress Booking and Rental Manager plugin <= 2.6.0 - Broken Access Control vulnerabilitymagepeopleteam Booking and Rental Manager
CVE-2026-23549WordPress WpEvently plugin <= 5.1.1 - PHP Object Injection vulnerabilitymagepeopleteam WpEvently
CVE-2026-17166Event Booking Manager for WooCommerce <= 5.3.7 - Missing Authorization to Authenticated (Contributor+) Site-Wide…magepeopleteam Event Booking Manager for WooCommerce – Sell…
CVE-2025-8898Taxi Booking Manager for Woocommerce | E-cab <= 1.3.0 - Missing Authorization to Unauthenticated Privilege Escalation…magepeopleteam E-cab Taxi Booking Manager for Woocommerce
CVE-2025-69328WordPress Booking and Rental Manager plugin <= 2.5.9 - PHP Object Injection vulnerabilitymagepeopleteam Booking and Rental Manager
CVE-2025-69327WordPress Car Rental Manager plugin <= 1.0.9 - Broken Access Control vulnerabilitymagepeopleteam Car Rental Manager
CVE-2025-66105WordPress Bus Ticket Booking with Seat Reservation plugin < 5.6.8 - Broken Access Control vulnerabilityMagepeople inc. Bus Ticket Booking with Seat Reservation
CVE-2025-66083WordPress WpEvently plugin <= 5.0.4 - Broken Access Control vulnerabilitymagepeopleteam WpEvently
CVE-2025-66082WordPress WpEvently plugin <= 5.0.4 - Broken Access Control vulnerabilitymagepeopleteam WpEvently
CVE-2025-64266WordPress Booking and Rental Manager plugin <= 2.5.4 - PHP Object Injection vulnerabilitymagepeopleteam Booking and Rental Manager
CVE-2025-5568WpEvently <= 4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scriptingmagepeopleteam Event Booking Manager for WooCommerce
CVE-2025-54742WordPress WpEvently Plugin <= 4.4.8 - PHP Object Injection Vulnerabilitymagepeopleteam WpEvently
CVE-2025-54713WordPress Taxi Booking Manager for WooCommerce plugin <= 1.3.0 - Broken Authentication vulnerabilitymagepeopleteam Taxi Booking Manager for WooCommerce
CVE-2025-54705WordPress WpEvently plugin <= 4.4.6 - Broken Access Control vulnerabilitymagepeopleteam WpEvently
CVE-2025-49904WordPress Booking and Rental Manager plugin <= 2.5.3 - Cross Site Scripting (XSS) vulnerabilitymagepeopleteam Booking and Rental Manager
CVE-2025-47585WordPress Booking and Rental Manager plugin <= 2.3.8 - Broken Access Control vulnerabilitymagepeopleteam Booking and Rental Manager
CVE-2025-39457WordPress Booking and Rental Manager plugin <= 2.2.8 - Broken Access Control vulnerabilitymagepeopleteam Booking and Rental Manager
CVE-2025-39390WordPress Booking and Rental Manager plugin <= 2.3.6 - Broken Access Control vulnerabilitymagepeopleteam Booking and Rental Manager
CVE-2025-32607WordPress WpBookingly plugin <= 1.3.0 - PHP Object Injection vulnerabilitymagepeopleteam WpBookingly
CVE-2025-32145WordPress WpEvently plugin <= 4.3.6 - PHP Object Injection vulnerabilitymagepeopleteam WpEvently
CVE-2025-30895WordPress WpEvently Plugin <= 4.2.9 - PHP Object Injection vulnerabilitymagepeopleteam WpEvently
CVE-2025-30892WordPress WpTravelly Plugin <= 1.8.7 - PHP Object Injection vulnerabilitymagepeopleteam WpTravelly
CVE-2025-30891WordPress WpTravelly Plugin <= 1.8.7 - Local File Inclusion vulnerabilitymagepeopleteam WpTravelly
CVE-2025-30887WordPress WpEvently Plugin <= 4.2.9 - Broken Access Control vulnerabilitymagepeopleteam WpEvently
CVE-2025-30839WordPress Taxi Booking Manager for WooCommerce plugin <= 1.2.1 - Broken Access Control vulnerabilitymagepeopleteam Taxi Booking Manager for WooCommerce
CVE-2025-27011WordPress Booking and Rental Manager plugin <= 2.2.8 - Local File Inclusion vulnerabilitymagepeopleteam Booking and Rental Manager
CVE-2025-26921WordPress Booking and Rental Manager Plugin <= 2.2.6 - PHP Object Injection vulnerabilitymagepeopleteam Booking and Rental Manager
CVE-2025-24661WordPress Taxi Booking Manager for WooCommerce plugin <= 1.1.8 - PHP Object Injection vulnerabilitymagepeopleteam Taxi Booking Manager for WooCommerce
CVE-2025-22737WordPress WpTravelly Plugin <= 1.8.5 - Broken Access Control vulnerabilitymagepeopleteam WpTravelly
CVE-2025-22720WordPress WpRently | WordPress plugin plugin <= 2.2.1 - Broken Access Control vulnerabilitymagepeopleteam Booking and Rental Manager
CVE-2024-49703WordPress WpEvently plugin <= 4.2.5 - Cross Site Scripting (XSS) vulnerabilitymagepeopleteam WpEvently
CVE-2024-49294WordPress WpBusTicketly plugin <= 5.4.3 - Cross Site Request Forgery (CSRF) vulnerabilitymagepeopleteam Bus Ticket Booking with Seat Reservation
CVE-2024-44037WordPress Multipurpose Ticket Booking Manager plugin <= 4.2.2 - Cross Site Scripting (XSS) vulnerabilitymagepeopleteam Multipurpose Ticket Booking Manager
CVE-2024-43986WordPress E-cab taxi booking manager plugin <=1.0.9 - Cross Site Scripting (XSS) vulnerabilityMagePeople Team Taxi Booking Manager for WooCommerce
CVE-2024-43985WordPress Bus Ticket Booking with Seat Reservation plugin <= 5.3.5 - Cross Site Scripting (XSS) vulnerabilityMagePeople Team Bus Ticket Booking with Seat Reservation
CVE-2024-43212WordPress WpTravelly plugin <= 1.7.7 - Broken Access Control vulnerabilityMagePeople Team WpTravelly
CVE-2024-43138WordPress Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 4.2.1 - Local File Inclusion vulnerabilityMagePeople Team Event Manager for WooCommerce
CVE-2024-32450WordPress WpTravelly plugin <= 1.6.0 - Cross Site Request Forgery (CSRF) vulnerabilityMagePeople Team WpTravelly
CVE-2024-32110WordPress Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 4.1.2 - Cross Site Request Forgery (CSRF)…Magepeople inc. WpEvently
CVE-2024-24796WordPress Event Manager for WooCommerce Plugin <= 4.1.1 is vulnerable to PHP Object InjectionMagePeople Team Event Manager and Tickets Selling Plugin…
CVE-2024-12412Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | WordPress plugin <=…magepeopleteam Booking and Rental Manager for Bike | Car |…
CVE-2024-0434WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly <= 1.7.1 - Missing Authorization via…magepeopleteam Travelly – Tour & Travel Booking Manager for…
CVE-2023-4067Bus Ticket Booking with Seat Reservation <= 5.2.3 - Reflected Cross-Site Scriptingmagepeopleteam Bus Ticket Booking with Seat Reservation
CVE-2023-36383WordPress Event Manager for WooCommerce Plugin <= 3.9.5 is vulnerable to Cross Site Scripting (XSS)MagePeople Team Event Manager and Tickets Selling Plugin…
CVE-2023-35048WordPress Booking and Rental Manager Plugin <= 1.2.1 is vulnerable to Cross Site Scripting (XSS)MagePeople Team Booking and Rental Manager for Bike
CVE-2023-30496WordPress Bus Ticket Booking with Seat Reservation Plugin <= 5.2.5 is vulnerable to Cross Site Scripting (XSS)MagePeople Team WpBusTicketly
CVE-2023-28422WordPress Event Manager for WooCommerce Plugin <= 3.8.6 is vulnerable to Cross Site Scripting (XSS)MagePeople Team Event Manager and Tickets Selling Plugin…
CVE-2022-47164WordPress Event Manager for WooCommerce Plugin <= 3.7.7 is vulnerable to Cross Site Request Forgery (CSRF)MagePeople Team Event Manager and Tickets Selling Plugin…
79 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.