WordPress security by component
The Events Calendar
Plugin description
The Events Calendar is a WordPress component with 25 published CVE records in this archive. The latest tracked vulnerability was published Jun 16, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
the-events-calendarLatest vulnerability
CVE-2026-49772: The Events Calendar: SQL injection
The Events Calendar is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is 6.15.12 through 6.16.2.
| Safe version |
|
||
|---|---|---|---|
| Jun 16, 2026 |
CVE-2026-49772
The Events Calendar: SQL injection
The Events Calendar is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is 6.15.12 through 6.16.2.
|
6.16.3 |
CVE9.3
NVDPending
|
| Mar 10, 2026 |
CVE-2026-3585
The Events Calendar: Filesystem traversal
The Events Calendar is affected by filesystem traversal. Exploitation requires at least author-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Feb 25, 2026 |
CVE-2026-2694
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Jan 20, 2026 |
CVE-2025-15043
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Jan 06, 2026 |
CVE-2025-69352
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Nov 05, 2025 |
CVE-2025-12197
The Events Calendar: SQL injection
The Events Calendar is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Oct 31, 2025 |
CVE-2025-12175
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Sep 16, 2025 |
CVE-2025-9808
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Sep 12, 2025 |
CVE-2025-9807
The Events Calendar: SQL injection
The Events Calendar is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Jun 11, 2025 |
CVE-2025-5144
The Events Calendar: Cross-site scripting
The Events Calendar is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 19, 2025 |
CVE-2025-48246
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| May 15, 2025 |
CVE-2024-8493
Events Calendar: Cross-site scripting
Events Calendar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Jan 27, 2025 |
CVE-2025-24537
The Events Calendar: Cross-site request forgery
The Events Calendar is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Jan 23, 2025 |
CVE-2024-12118
The Events Calendar: Cross-site scripting
The Events Calendar is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jan 02, 2025 |
CVE-2024-37518
The Events Calendar: Cross-site request forgery
The Events Calendar is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Dec 16, 2024 |
CVE-2024-5333
Events Calendar: A security weakness
Events Calendar is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Dec 13, 2024 |
CVE-2023-35777
The Events Calendar: A security weakness
The Events Calendar is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Sep 27, 2024 |
CVE-2024-6931
The Events Calendar: Cross-site scripting
The Events Calendar is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Sep 25, 2024 |
CVE-2024-8275
The Events Calendar: SQL injection
The Events Calendar is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Jun 14, 2024 |
CVE-2024-1295
events-calendar-pro: A security weakness
events-calendar-pro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Jun 04, 2024 |
CVE-2024-4180
Events Calendar: A security weakness
Events Calendar is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.1
NVDPending
|
| Apr 15, 2024 |
CVE-2024-31433
The Events Calendar: Cross-site request forgery
The Events Calendar is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Feb 05, 2024 |
CVE-2023-6557
The Events Calendar: Sensitive information exposure
The Events Calendar is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Dec 18, 2023 |
CVE-2023-6203
Events Calendar: A security weakness
Events Calendar is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Aug 21, 2019 |
CVE-2019-15109
The Events Calendar: Cross-site scripting
The Events Calendar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|