Stellarwp The Events Calendar vulnerabilities
24 known vulnerabilities affecting stellarwp/the_events_calendar.
Total CVEs
24
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH4MEDIUM14UNKNOWN4
Vulnerabilities
Page 1 of 2
CVE-2026-3585HIGHCVSS 7.5≤ 6.15.172026-03-10
CVE-2026-3585 [HIGH] CWE-22 CVE-2026-3585: The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to,
The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.17 via the 'ajax_create_import' function. This makes it possible for authenticated attackers, with Author-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
cvelistv5nvd
CVE-2026-2694MEDIUMCVSS 5.4≤ 6.15.162026-02-25
CVE-2026-2694 [MEDIUM] CWE-285 CVE-2026-2694: The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and
The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to an improper capability check on the 'can_edit' and 'can_delete' function in all versions up to, and including, 6.15.16. This makes it possible for authenticated attackers, with Contributor-level access and above, to update or trash ev
cvelistv5nvd
CVE-2025-15043MEDIUMCVSS 5.4≤ 6.15.132026-01-20
CVE-2025-15043 [MEDIUM] CWE-862 CVE-2025-15043: The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing c
The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'start_migration', 'cancel_migration', and 'revert_migration' functions in all versions up to, and including, 6.15.13. This makes it possible for authenticated attackers, with subscriber level access and above, to start, cancel,
cvelistv5nvd
CVE-2025-69352MEDIUMCVSS 5.4≤ 6.15.12.22026-01-06
CVE-2025-69352 [MEDIUM] CWE-862 CVE-2025-69352: Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Expl
Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through <= 6.15.12.2.
cvelistv5nvd
CVE-2025-12197HIGHCVSS 7.5≥ 6.15.1.1, ≤ 6.15.92025-11-05
CVE-2025-12197 [HIGH] CWE-89 CVE-2025-12197: The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parame
The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15.1.1 to 6.15.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into alread
cvelistv5nvd
CVE-2025-12192MEDIUMCVSS 5.3≤ 6.15.92025-11-05
CVE-2025-12192 [MEDIUM] CWE-697 CVE-2025-12192: The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to,
The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.9. The sysinfo REST endpoint compares the provided key to the stored opt-in key using a loose comparison, allowing unauthenticated attackers to send a boolean value and obtain the full system report whenever "Yes, automatically shar
cvelistv5nvd
CVE-2025-12175MEDIUMCVSS 4.3≤ 6.15.92025-10-31
CVE-2025-12175 [MEDIUM] CWE-862 CVE-2025-12175: The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing c
The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'tec_qr_code_modal' AJAX endpoint in all versions up to, and including, 6.15.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view draft event names and generate/view QR codes for
cvelistv5nvd
CVE-2025-9808MEDIUMCVSS 5.3PoC≤ 6.15.22025-09-16
CVE-2025-9808 [MEDIUM] CWE-200 CVE-2025-9808: The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions u
The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract information about password-protected vendors or venues.
cvelistv5nvd
CVE-2025-9807HIGHCVSS 7.5≤ 6.15.12025-09-12
CVE-2025-9807 [HIGH] CWE-89 CVE-2025-9807: The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ p
The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all versions up to, and including, 6.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL qu
cvelistv5nvd
CVE-2025-5144MEDIUMCVSS 5.4fixed in 6.13.2.1≤ 6.13.22025-06-11
CVE-2025-5144 [MEDIUM] CWE-79 CVE-2025-5144: The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘d
The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, 6.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts i
cvelistv5nvd
CVE-2025-48246UNKNOWN≤ 6.11.2.12025-05-19
CVE-2025-48246 CWE-862 CVE-2025-48246: Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Expl
Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through <= 6.11.2.1.
cvelistv5nvd
CVE-2024-8493MEDIUMCVSS 4.8fixed in 6.6.42025-05-15
CVE-2024-8493 [MEDIUM] CWE-79 CVE-2024-8493: The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings,
The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
nvd
CVE-2025-24537UNKNOWN≤ 6.7.02025-01-27
CVE-2025-24537 CWE-352 CVE-2025-24537: Cross-Site Request Forgery (CSRF) vulnerability in StellarWP The Events Calendar the-events-calendar
Cross-Site Request Forgery (CSRF) vulnerability in StellarWP The Events Calendar the-events-calendar allows Cross Site Request Forgery.This issue affects The Events Calendar: from n/a through <= 6.7.0.
cvelistv5nvd
CVE-2024-12118MEDIUMCVSS 5.4≤ 6.9.02025-01-23
CVE-2024-12118 [MEDIUM] CWE-79 CVE-2024-12118: The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Ev
The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget through the html_tag attribute in all versions up to, and including, 6.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,
cvelistv5nvd
CVE-2024-37518UNKNOWN≤ 6.5.1.42025-01-02
CVE-2024-37518 CWE-352 CVE-2024-37518: Cross-Site Request Forgery (CSRF) vulnerability in StellarWP The Events Calendar the-events-calendar
Cross-Site Request Forgery (CSRF) vulnerability in StellarWP The Events Calendar the-events-calendar allows Cross Site Request Forgery.This issue affects The Events Calendar: from n/a through <= 6.5.1.4.
cvelistv5nvd
CVE-2024-5333MEDIUMCVSS 5.3PoCfixed in 6.8.2.12024-12-16
CVE-2024-5333 [MEDIUM] CWE-639 CVE-2024-5333: The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowi
The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.
nvd
CVE-2022-4974MEDIUMCVSS 6.3fixed in 5.14.0.42024-10-16
CVE-2022-4974 [MEDIUM] CWE-862 CVE-2022-4974: The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cr
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme runni
cvelistv5nvd
CVE-2024-6931MEDIUMCVSS 6.1fixed in 6.6.4≤ 6.6.32024-09-27
CVE-2024-6931 [HIGH] CWE-79 CVE-2024-6931: The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP n
The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an in
cvelistv5nvd
CVE-2024-8275CRITICALCVSS 9.8fixed in 6.6.4.1≤ 6.6.42024-09-25
CVE-2024-8275 [CRITICAL] CWE-89 CVE-2024-8275: The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' paramete
The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated at
cvelistv5nvd
CVE-2024-4180CRITICALCVSS 9.1PoCfixed in 6.4.0.12024-06-04
CVE-2024-4180 [CRITICAL] CWE-79 CVE-2024-4180: The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted conten
The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.
nvd
1 / 2Next →