← WordPress Vulnerabilities
WordPress security by component

The Events Calendar

The Events Calendar is a WordPress component with 25 published CVE records in this archive. The latest tracked vulnerability was published Jun 16, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: the-events-calendar

CVE-2026-49772: The Events Calendar: SQL injection

The Events Calendar is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is 6.15.12 through 6.16.2.

PublishedJun 16, 2026
Known safe version6.16.3
Safe version
Jun 16, 2026 CVE-2026-49772
The Events Calendar: SQL injection
The Events Calendar is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is 6.15.12 through 6.16.2.
6.16.3
CVE9.3
NVDPending
Mar 10, 2026 CVE-2026-3585
The Events Calendar: Filesystem traversal
The Events Calendar is affected by filesystem traversal. Exploitation requires at least author-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending
Feb 25, 2026 CVE-2026-2694
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Jan 20, 2026 CVE-2025-15043
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Jan 06, 2026 CVE-2025-69352
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Nov 05, 2025 CVE-2025-12197
The Events Calendar: SQL injection
The Events Calendar is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVDPending
Oct 31, 2025 CVE-2025-12175
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Sep 16, 2025 CVE-2025-9808
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Sep 12, 2025 CVE-2025-9807
The Events Calendar: SQL injection
The Events Calendar is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVDPending
Jun 11, 2025 CVE-2025-5144
The Events Calendar: Cross-site scripting
The Events Calendar is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 19, 2025 CVE-2025-48246
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
May 15, 2025 CVE-2024-8493
Events Calendar: Cross-site scripting
Events Calendar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Jan 27, 2025 CVE-2025-24537
The Events Calendar: Cross-site request forgery
The Events Calendar is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVDPending
Jan 23, 2025 CVE-2024-12118
The Events Calendar: Cross-site scripting
The Events Calendar is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jan 02, 2025 CVE-2024-37518
The Events Calendar: Cross-site request forgery
The Events Calendar is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Dec 16, 2024 CVE-2024-5333
Events Calendar: A security weakness
Events Calendar is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 13, 2024 CVE-2023-35777
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Sep 27, 2024 CVE-2024-6931
The Events Calendar: Cross-site scripting
The Events Calendar is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Sep 25, 2024 CVE-2024-8275
The Events Calendar: SQL injection
The Events Calendar is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVDPending
Jun 14, 2024 CVE-2024-1295
events-calendar-pro: A security weakness
events-calendar-pro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD6.5
Jun 04, 2024 CVE-2024-4180
Events Calendar: A security weakness
Events Calendar is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.1
NVDPending
Apr 15, 2024 CVE-2024-31433
The Events Calendar: Cross-site request forgery
The Events Calendar is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Feb 05, 2024 CVE-2023-6557
The Events Calendar: Sensitive information exposure
The Events Calendar is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVD5.3
Dec 18, 2023 CVE-2023-6203
Events Calendar: A security weakness
Events Calendar is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Aug 21, 2019 CVE-2019-15109
The Events Calendar: Cross-site scripting
The Events Calendar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1