← WordPress Vulnerabilities
WordPress security by component

Event List

Event List is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Aug 26, 2025; the highest CVE/CNA score is 8.8.

Plugin slug: event-list

CVE-2025-6366: Event List: Privilege escalation or authentication bypass

Event List is affected by privilege escalation or authentication bypass. Exploitation requires at least subscriber-level access. A successful request can grant permissions or access that the caller should not possess.

PublishedAug 26, 2025
Safe version guidanceSee mitigation notes
Safe version
Aug 26, 2025 CVE-2025-6366
Event List: Privilege escalation or authentication bypass
Event List is affected by privilege escalation or authentication bypass. Exploitation requires at least subscriber-level access. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
May 02, 2022 CVE-2022-0418
Event List: Cross-site scripting
Event List is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Aug 01, 2017 CVE-2017-12068
Event List: Cross-site scripting
Event List is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jun 13, 2017 CVE-2017-9429
Event List: SQL injection
Event List is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8