← WordPress Vulnerabilities
WordPress security by component

The Events Calendar

The Events Calendar creates and manages events, calendars, venues, organizers, schedules, and event display pages within WordPress.

The Events Calendar (the-events-calendar) is a WordPress plugin with 28 published CVE records in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 9.8.

Plugin slug: the-events-calendar

CVE-2026-78159: The Events Calendar comment blocks reach a callable execution sink

The Events Calendar through 6.17.3 can execute code without authentication when comments are enabled on tribe_events posts. A crafted wp:legacy-widget block in a comment supplies a plain-array widget classes map that bypasses is_safe_widget_instance() and reaches the callable sink in Element_Classes::parse_array() when do_blocks() processes the single-event comment area.

PublishedSep 12, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for the-events-calendar
Safe version
Sep 12, 2026 CVE-2026-78159
The Events Calendar comment blocks reach a callable execution sink
The Events Calendar through 6.17.3 can execute code without authentication when comments are enabled on tribe_events posts. A crafted wp:legacy-widget block in a comment supplies a plain-array widget classes map that bypasses is_safe_widget_instance() and reaches the callable sink in Element_Classes::parse_array() when do_blocks() processes the single-event comment area.
See mitigation notes
CVE9.8
NVDPending
Sep 12, 2026 CVE-2026-78006
The Events Calendar pending comments can trigger object injection
The Events Calendar through 6.17.4 can execute code without authentication when comments are enabled and visible on events. Its V2 single-event template runs do_blocks() over buffered comment HTML; a moderation-hash URL lets the commenter view a pending crafted block immediately. PHP magic methods bypass is_safe_widget_instance(), enable_rendering_widget_copied() forges a valid wp_hash attribute, and attacker data reaches unserialize().
See mitigation notes
CVE9.8
NVDPending
Aug 24, 2026 CVE-2026-78265
The Events Calendar permits unauthenticated PHP object injection
The Events Calendar through 6.17.2 permits an unauthenticated attacker to supply serialized data to an unsafe PHP deserialization operation. A usable object chain can compromise site confidentiality, integrity, and availability.
6.17.3
CVE9.8
NVDPending
Jun 16, 2026 CVE-2026-49772
The Events Calendar: SQL injection
The Events Calendar is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is 6.15.12 through 6.16.2.
6.16.3
CVE9.3
NVDPending
Mar 10, 2026 CVE-2026-3585
The Events Calendar: Filesystem traversal
The Events Calendar is affected by filesystem traversal. Exploitation requires an authenticated author account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending
Feb 25, 2026 CVE-2026-2694
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Jan 20, 2026 CVE-2025-15043
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Jan 06, 2026 CVE-2025-69352
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Nov 05, 2025 CVE-2025-12197
The Events Calendar: SQL injection
The Events Calendar is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVDPending
Oct 31, 2025 CVE-2025-12175
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Sep 16, 2025 CVE-2025-9808
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Sep 12, 2025 CVE-2025-9807
The Events Calendar: SQL injection
The Events Calendar is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVDPending
Jun 11, 2025 CVE-2025-5144
The Events Calendar: Cross-site scripting
The Events Calendar is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 19, 2025 CVE-2025-48246
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
May 15, 2025 CVE-2024-8493
Events Calendar: Cross-site scripting
Events Calendar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Jan 27, 2025 CVE-2025-24537
The Events Calendar: Cross-site request forgery
The Events Calendar is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVDPending
Jan 23, 2025 CVE-2024-12118
The Events Calendar: Cross-site scripting
The Events Calendar is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jan 02, 2025 CVE-2024-37518
The Events Calendar: Cross-site request forgery
The Events Calendar is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Dec 16, 2024 CVE-2024-5333
Events Calendar: A security weakness
Events Calendar is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 13, 2024 CVE-2023-35777
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Sep 27, 2024 CVE-2024-6931
The Events Calendar: Cross-site scripting
The Events Calendar is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Sep 25, 2024 CVE-2024-8275
The Events Calendar: SQL injection
The Events Calendar is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVDPending
Jun 14, 2024 CVE-2024-1295
events-calendar-pro: A security weakness
events-calendar-pro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD6.5
Jun 04, 2024 CVE-2024-4180
Events Calendar: A security weakness
Events Calendar is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.1
NVDPending
Apr 15, 2024 CVE-2024-31433
The Events Calendar: Cross-site request forgery
The Events Calendar is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Feb 05, 2024 CVE-2023-6557
The Events Calendar: Sensitive information exposure
The Events Calendar is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVD5.3
Dec 18, 2023 CVE-2023-6203
Events Calendar: A security weakness
Events Calendar is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD7.5
Aug 21, 2019 CVE-2019-15109
The Events Calendar: Cross-site scripting
The Events Calendar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1