← WordPress Vulnerabilities
WordPress security by component

Events Calendar for GeoDirectory

Events Calendar for GeoDirectory is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: events-for-geodirectory

CVE-2026-39532: Events Calendar for GeoDirectory: Code execution

Events Calendar for GeoDirectory is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 2.3.25.

PublishedJun 15, 2026
Known safe version2.3.26
Safe version
Jun 15, 2026 CVE-2026-39532
Events Calendar for GeoDirectory: Code execution
Events Calendar for GeoDirectory is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 2.3.25.
2.3.26
CVE8.8
NVDPending
Jun 09, 2026 CVE-2026-11616
Events Calendar for GeoDirectory: Privilege escalation or authentication bypass
Events Calendar for GeoDirectory is affected by privilege escalation or authentication bypass. Exploitation requires at least subscriber-level access. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 2.3.28.
> 2.3.28
CVE8.8
NVDPending