WordPress security by component
The Events Calendar
Plugin description
The Events Calendar creates and manages events, calendars, venues, organizers, schedules, and event display pages within WordPress.
The Events Calendar (the-events-calendar) is a WordPress plugin with 28 published CVE records in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
the-events-calendarLatest vulnerability
CVE-2026-78159: The Events Calendar comment blocks reach a callable execution sink
The Events Calendar through 6.17.3 can execute code without authentication when comments are enabled on tribe_events posts. A crafted wp:legacy-widget block in a comment supplies a plain-array widget classes map that bypasses is_safe_widget_instance() and reaches the callable sink in Element_Classes::parse_array() when do_blocks() processes the single-event comment area.
| Safe version |
|
||
|---|---|---|---|
| Sep 12, 2026 |
CVE-2026-78159
The Events Calendar comment blocks reach a callable execution sink
The Events Calendar through 6.17.3 can execute code without authentication when comments are enabled on tribe_events posts. A crafted wp:legacy-widget block in a comment supplies a plain-array widget classes map that bypasses is_safe_widget_instance() and reaches the callable sink in Element_Classes::parse_array() when do_blocks() processes the single-event comment area.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Sep 12, 2026 |
CVE-2026-78006
The Events Calendar pending comments can trigger object injection
The Events Calendar through 6.17.4 can execute code without authentication when comments are enabled and visible on events. Its V2 single-event template runs do_blocks() over buffered comment HTML; a moderation-hash URL lets the commenter view a pending crafted block immediately. PHP magic methods bypass is_safe_widget_instance(), enable_rendering_widget_copied() forges a valid wp_hash attribute, and attacker data reaches unserialize().
|
See mitigation notes |
CVE9.8
NVDPending
|
| Aug 24, 2026 |
CVE-2026-78265
The Events Calendar permits unauthenticated PHP object injection
The Events Calendar through 6.17.2 permits an unauthenticated attacker to supply serialized data to an unsafe PHP deserialization operation. A usable object chain can compromise site confidentiality, integrity, and availability.
|
6.17.3 |
CVE9.8
NVDPending
|
| Jun 16, 2026 |
CVE-2026-49772
The Events Calendar: SQL injection
The Events Calendar is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is 6.15.12 through 6.16.2.
|
6.16.3 |
CVE9.3
NVDPending
|
| Mar 10, 2026 |
CVE-2026-3585
The Events Calendar: Filesystem traversal
The Events Calendar is affected by filesystem traversal. Exploitation requires an authenticated author account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Feb 25, 2026 |
CVE-2026-2694
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Jan 20, 2026 |
CVE-2025-15043
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Jan 06, 2026 |
CVE-2025-69352
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Nov 05, 2025 |
CVE-2025-12197
The Events Calendar: SQL injection
The Events Calendar is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Oct 31, 2025 |
CVE-2025-12175
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Sep 16, 2025 |
CVE-2025-9808
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Sep 12, 2025 |
CVE-2025-9807
The Events Calendar: SQL injection
The Events Calendar is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Jun 11, 2025 |
CVE-2025-5144
The Events Calendar: Cross-site scripting
The Events Calendar is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 19, 2025 |
CVE-2025-48246
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| May 15, 2025 |
CVE-2024-8493
Events Calendar: Cross-site scripting
Events Calendar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Jan 27, 2025 |
CVE-2025-24537
The Events Calendar: Cross-site request forgery
The Events Calendar is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Jan 23, 2025 |
CVE-2024-12118
The Events Calendar: Cross-site scripting
The Events Calendar is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jan 02, 2025 |
CVE-2024-37518
The Events Calendar: Cross-site request forgery
The Events Calendar is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Dec 16, 2024 |
CVE-2024-5333
Events Calendar: A security weakness
Events Calendar is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Dec 13, 2024 |
CVE-2023-35777
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Sep 27, 2024 |
CVE-2024-6931
The Events Calendar: Cross-site scripting
The Events Calendar is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Sep 25, 2024 |
CVE-2024-8275
The Events Calendar: SQL injection
The Events Calendar is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Jun 14, 2024 |
CVE-2024-1295
events-calendar-pro: A security weakness
events-calendar-pro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Jun 04, 2024 |
CVE-2024-4180
Events Calendar: A security weakness
Events Calendar is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.1
NVDPending
|
| Apr 15, 2024 |
CVE-2024-31433
The Events Calendar: Cross-site request forgery
The Events Calendar is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Feb 05, 2024 |
CVE-2023-6557
The Events Calendar: Sensitive information exposure
The Events Calendar is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Dec 18, 2023 |
CVE-2023-6203
Events Calendar: A security weakness
Events Calendar is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD7.5
|
| Aug 21, 2019 |
CVE-2019-15109
The Events Calendar: Cross-site scripting
The Events Calendar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|