A vulnerability was found in Events Manager Plugin up to 7.2.2.1 on WordPress. It has been rated as problematic. This vulnerability affects the function events_list_grouped of the component Shortcode Handler. The manipulation leads to cross site scripting.

This vulnerability is listed as CVE-2025-12976. The attack may be initiated remotely. There is no available exploit.