plugin

Community Events Vulnerabilities

26 known security issues reported for the Community Events WordPress plugin. Most recent disclosed Mar 7, 2026.

3 critical 3 high 7 medium

Running Community Events on your site? Check whether your installed version is affected.

Scan your site free

Community Events - Authenticated (Administrator+) SQL Injection via 'ce_venue_name' CSV Field vulnerability

high

Authenticated (Administrator+) SQL Injection via 'ce_venue_name' CSV Field vulnerability

CVSS:
7.6
Affected:
up to 1.5.8
Fixed in:
1.5.9
Disclosed:
Mar 7, 2026

Community Events <= 1.5.8 - Authenticated (Administrator+) SQL Injection via 'ce_venue_name' CSV Field

medium

The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'ce_venue_name' CSV field in the `on_save_changes_venues` function in all versions up to, and including, 1.5.8. This is due to insufficient escaping on the user-supplied CSV data and lack of sufficient preparation on the existing SQL query...

CVSS:
4.9
Affected:
up to 1.5.8
Fixed in:
1.5.9
Disclosed:
Mar 6, 2026

CVE-2026-2429 on NVD →

Community Events <= 1.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'ce_venue_name' Parameter

medium

The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ce_venue_name' parameter in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above,...

CVSS:
4.4
Affected:
up to 1.5.7
Fixed in:
1.5.8
Disclosed:
Feb 17, 2026

CVE-2026-1649 on NVD →

Community Events [community-events] < 1.5.7

unknown

[en] The Community Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_admin_event_approval() function in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to approve arbitrary events via the 'eventlist...

Affected:
up to 1.5.7
Fixed in:
1.5.7
Disclosed:
Jan 17, 2026

CVE-2025-14029 on NVD →

Community Events <= 1.5.6 - Missing Authorization to Unauthenticated Arbitrary Event Approval via 'eventlist' Parameter

medium

The Community Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_admin_event_approval() function in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to approve arbitrary events via the 'eventlist' par...

CVSS:
5.3
Affected:
up to 1.5.6
Fixed in:
1.5.7
Disclosed:
Jan 16, 2026

CVE-2025-14029 on NVD →

Community Events [community-events] < 1.5.5

unknown

[en] The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated at...

Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Nov 19, 2025

CVE-2025-12646 on NVD →

Community Events <= 1.5.4 - Unauthenticated SQL Injection

high

The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attacke...

CVSS:
7.5
Affected:
up to 1.5.4
Fixed in:
1.5.5
Disclosed:
Nov 18, 2025

CVE-2025-12646 on NVD →

Community Events [community-events] < 1.5.3

unknown

[en] The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event details parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
Nov 1, 2025

CVE-2025-11995 on NVD →

Community Events <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting

high

The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event details parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wi...

CVSS:
7.2
Affected:
up to 1.5.2
Fixed in:
1.5.3
Disclosed:
Oct 31, 2025

CVE-2025-11995 on NVD →

Community Events [community-events] < 1.5.2

unknown

[en] The Community Events plugin for WordPress is vulnerable to SQL Injection via the ‘event_venue’ parameter in all versions up to, and including, 1.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated at...

Affected:
up to 1.5.2
Fixed in:
1.5.2
Disclosed:
Oct 9, 2025

CVE-2025-10586 on NVD →

Community Events <= 1.5.1 - Unauthenticated SQL Injection

critical

The Community Events plugin for WordPress is vulnerable to SQL Injection via the ‘event_venue’ parameter in all versions up to, and including, 1.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attacke...

CVSS:
9.8
Affected:
up to 1.5.1
Fixed in:
1.5.2
Disclosed:
Oct 8, 2025

CVE-2025-10586 on NVD →

Community Events [community-events] < 1.5.2

unknown

[en] The Community Events plugin for WordPress is vulnerable to SQL Injection via the event_category parameter in all versions up to, and including, 1.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated a...

Affected:
up to 1.5.2
Fixed in:
1.5.2
Disclosed:
Oct 8, 2025

CVE-2025-10587 on NVD →

Community Events <= 1.5.1 - Unauthenticated SQL Injection

critical

The Community Events plugin for WordPress is vulnerable to SQL Injection via the event_category parameter in all versions up to, and including, 1.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attack...

CVSS:
9.8
Affected:
up to 1.5.1
Fixed in:
1.5.2
Disclosed:
Oct 7, 2025

CVE-2025-10587 on NVD →

Community Events [community-events] < 1.5.1

unknown

[en] The Community Events WordPress plugin before 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 1.5.1
Fixed in:
1.5.1
Disclosed:
Aug 5, 2024

CVE-2024-6270 on NVD →

Community Events [community-events] < 1.5

unknown

[en] The Community Events WordPress plugin before 1.5 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin delete arbitrary events via a CSRF attack

Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
Jul 22, 2024

CVE-2024-6271 on NVD →

Community Events <= 1.5 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject ar...

CVSS:
4.4
Affected:
up to 1.5
Fixed in:
1.5.1
Disclosed:
Jul 15, 2024

CVE-2024-6270 on NVD →

Community Events <= 1.4.9 - Cross-Site Request Forgery

medium

The Community Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.9. This is due to missing or incorrect nonce validation on the on_show_page() function. This makes it possible for unauthenticated attackers to delete events via a forged request granted they...

CVSS:
4.3
Affected:
up to 1.4.9
Fixed in:
1.5
Disclosed:
Jul 1, 2024

CVE-2024-6271 on NVD →

Community Events [community-events] < 1.4.9

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting vulnerability in Yannick Lefebvre Community Events plugin <= 1.4.8 versions.

Affected:
up to 1.4.9
Fixed in:
1.4.9
Disclosed:
Mar 23, 2023

CVE-2022-44742 on NVD →

Community Events <= 1.4.8 - Authenticated (Administrator+) Stored Cross Site Scripting

medium

The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...

CVSS:
5.5
Affected:
up to 1.4.8
Fixed in:
1.4.9
Disclosed:
Nov 25, 2022

CVE-2022-44742 on NVD →

Community Events [community-events] < 1.4.8

unknown

[en] The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

Affected:
up to 1.4.8
Fixed in:
1.4.8
Disclosed:
Aug 2, 2021

CVE-2021-24496 on NVD →

Community Events <= 1.4.7 - Reflected Cross-Site Scripting

medium

The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

CVSS:
6.1
Affected:
up to 1.4.8
Fixed in:
1.4.8
Disclosed:
Jul 2, 2021

CVE-2021-24496 on NVD →

Community Events [community-events] < 1.4

unknown

[en] SQL injection vulnerability in WordPress Community Events plugin before 1.4.

Affected:
up to 1.4
Fixed in:
1.4
Disclosed:
Sep 7, 2017

CVE-2015-3313 on NVD →

Community Events [community-events] < 1.3.6

unknown

This WordPress Community Events plugin is prone to an SQL injection. If there is at least one planned event on the calendar, this vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Upgrade the plugin.

Affected:
up to 1.3.6
Fixed in:
1.3.6
Disclosed:
Apr 21, 2015

Community Events < 1.4 - SQL Injection

critical

The Community Events plugin for WordPress is vulnerable to SQL Injection via the ‘page_id’ parameter in versions up to, and including, 1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to ap...

CVSS:
9.8
Affected:
up to 1.3
Fixed in:
1.4
Disclosed:
Apr 20, 2015

CVE-2015-3313 on NVD →

Community Events [community-events] < 1.2.2

unknown

Sermon Browser plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Update the plugin.

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Sep 8, 2011

Community Events [community-events] < 1.2.3

unknown

The Community Events WordPress plugin was affected by a SQL Injection security vulnerability.

Affected:
up to 1.2.3
Fixed in:
1.2.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database