plugin

The Events Calendar Vulnerabilities

70 known security issues reported for the The Events Calendar WordPress plugin. Most recent disclosed Jul 6, 2026.

1 critical 6 high 24 medium

Running The Events Calendar on your site? Check whether your installed version is affected.

Scan your site free

The Events Calendar <= 6.16.5.0 - Missing Authorization

medium

The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.16.5.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 6.16.5.0
Fixed in:
6.16.5.1
Disclosed:
Jul 6, 2026

CVE-2026-13390 on NVD →

The Events Calendar 6.15.12-6.16.2 - Unauthenticated SQL Injection

high

The The Events Calendar plugin for WordPress is vulnerable to SQL Injection in versions up to 6.15.12-6.16.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries int...

CVSS:
7.5
Affected:
6.15.12 – 6.16.2
Fixed in:
6.16.3
Disclosed:
Jun 8, 2026

CVE-2026-49772 on NVD →

The Events Calendar - Authenticated (Author+) Arbitrary File Read via ajax_create_import vulnerability

high

Authenticated (Author+) Arbitrary File Read via ajax_create_import vulnerability

CVSS:
7.5
Affected:
up to 6.15.17
Fixed in:
6.15.17.1
Disclosed:
Mar 11, 2026

The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_import

high

The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.17 via the 'ajax_create_import' function. This makes it possible for authenticated attackers, with Author-level access and above, to read the contents of arbitrary files on the server, which can conta...

CVSS:
7.5
Affected:
up to 6.15.17
Fixed in:
6.15.17.1
Disclosed:
Mar 9, 2026

CVE-2026-3585 on NVD →

The Events Calendar <= 6.15.16 - Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API

medium

The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to an improper capability check on the 'can_edit' and 'can_delete' function in all versions up to, and including, 6.15.16. This makes it possible for authenticated attackers, with Contributor-level acces...

CVSS:
5.4
Affected:
up to 6.15.16
Fixed in:
6.15.16.1
Disclosed:
Feb 25, 2026

CVE-2026-2694 on NVD →

The Events Calendar <= 6.15.13 - Missing Authorization to Authenticated (Subscriber+) Data Migration Control

medium

The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'start_migration', 'cancel_migration', and 'revert_migration' functions in all versions up to, and including, 6.15.13. This makes it possible for authenticated attackers, with subscriber level acce...

CVSS:
5.4
Affected:
up to 6.15.13
Fixed in:
6.15.13.1
Disclosed:
Jan 20, 2026

CVE-2025-15043 on NVD →

The Events Calendar [the-events-calendar] < 6.15.13.1

unknown

[en] The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'start_migration', 'cancel_migration', and 'revert_migration' functions in all versions up to, and including, 6.15.13. This makes it possible for authenticated attackers, with subscriber level...

Affected:
up to 6.15.13.1
Fixed in:
6.15.13.1
Disclosed:
Jan 20, 2026

CVE-2025-15043 on NVD →

The Events Calendar <= 6.15.12.2 - Missing Authorization

medium

The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.15.12.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 6.15.12.2
Fixed in:
6.15.13
Disclosed:
Jan 9, 2026

CVE-2025-69352 on NVD →

The Events Calendar [the-events-calendar] <= 6.15.12.2 (unfixed)

unknown

[en] Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through <= 6.15.12.2.

Affected:
up to 6.15.12.2
Fix:
No patched version reported
Disclosed:
Jan 6, 2026

CVE-2025-69352 on NVD →

The Events Calendar [the-events-calendar] < 6.15.10

unknown

[en] The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.9. The sysinfo REST endpoint compares the provided key to the stored opt-in key using a loose comparison, allowing unauthenticated attackers to send a boolean value and obtain the full system rep...

Affected:
up to 6.15.10
Fixed in:
6.15.10
Disclosed:
Nov 5, 2025

CVE-2025-12192 on NVD →

The Events Calendar [the-events-calendar] < 6.15.10

unknown

[en] The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15.1.1 to 6.15.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to a...

Affected:
up to 6.15.10
Fixed in:
6.15.10
Disclosed:
Nov 5, 2025

CVE-2025-12197 on NVD →

The Events Calendar <= 6.15.9 - Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information Exposure

medium

The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.9. The sysinfo REST endpoint compares the provided key to the stored opt-in key using a loose comparison, allowing unauthenticated attackers to send a boolean value and obtain the full system report w...

CVSS:
5.3
Affected:
up to 6.15.9
Fixed in:
6.15.10
Disclosed:
Nov 4, 2025

CVE-2025-12192 on NVD →

The Events Calendar 6.15.1.1 - 6.15.9 - Unauthenticated SQL Injection via s

high

The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15.1.1 to 6.15.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append...

CVSS:
7.5
Affected:
6.15.1.1 – 6.15.9
Fixed in:
6.15.10
Disclosed:
Nov 4, 2025

CVE-2025-12197 on NVD →

The Events Calendar [the-events-calendar] < 6.15.10

unknown

[en] The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'tec_qr_code_modal' AJAX endpoint in all versions up to, and including, 6.15.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view draft event...

Affected:
up to 6.15.10
Fixed in:
6.15.10
Disclosed:
Oct 31, 2025

CVE-2025-12175 on NVD →

The Events Calendar <= 6.15.9 - Missing Authorization to Authenticated (Subscriber+) Draft Event Title/QR Code Exposure

medium

The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'tec_qr_code_modal' AJAX endpoint in all versions up to, and including, 6.15.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view draft event names...

CVSS:
4.3
Affected:
up to 6.15.9
Fixed in:
6.15.10
Disclosed:
Oct 30, 2025

CVE-2025-12175 on NVD →

The Events Calendar <= 6.15.2 - Missing Authorization to Unauthenticated Password-Protected Information Disclosure

medium

The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract information about password-protected vendors or venues.

CVSS:
5.3
Affected:
up to 6.15.2
Fixed in:
6.15.3
Disclosed:
Sep 15, 2025

CVE-2025-9808 on NVD →

The Events Calendar <= 6.15.1 - Unauthenticated SQL Injection

high

The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all versions up to, and including, 6.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated...

CVSS:
7.5
Affected:
up to 6.15.1
Fixed in:
6.15.1.1
Disclosed:
Sep 11, 2025

CVE-2025-9807 on NVD →

The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

medium

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, 6.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,...

CVSS:
6.4
Affected:
up to 6.13.2
Fixed in:
6.13.2.1
Disclosed:
Jun 10, 2025

CVE-2025-5144 on NVD →

The Events Calendar <= 6.11.2.1 - Missing Authorization

medium

The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax_preview_import() function in versions up to, and including, 6.11.2.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to create an import.

CVSS:
4.3
Affected:
up to 6.11.2.1
Fixed in:
6.12.0
Disclosed:
May 19, 2025

CVE-2025-48246 on NVD →

The Events Calendar [the-events-calendar] < 6.12.0

unknown

[en] Missing Authorization vulnerability in The Events Calendar The Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Events Calendar: from n/a through 6.11.2.1.

Affected:
up to 6.12.0
Fixed in:
6.12.0
Disclosed:
May 19, 2025

CVE-2025-48246 on NVD →

The Events Calendar [the-events-calendar] < 6.7.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in The Events Calendar The Events Calendar allows Cross Site Request Forgery. This issue affects The Events Calendar: from n/a through 6.7.0.

Affected:
up to 6.7.1
Fixed in:
6.7.1
Disclosed:
Jan 27, 2025

CVE-2025-24537 on NVD →

The Events Calendar [the-events-calendar] < 6.9.1

unknown

[en] The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget through the html_tag attribute in all versions up to, and including, 6.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wit...

Affected:
up to 6.9.1
Fixed in:
6.9.1
Disclosed:
Jan 23, 2025

CVE-2024-12118 on NVD →

The Events Calendar <= 6.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget through the html_tag attribute in all versions up to, and including, 6.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Con...

CVSS:
6.4
Affected:
up to 6.9.0
Fixed in:
6.9.1
Disclosed:
Jan 22, 2025

CVE-2024-12118 on NVD →

The Events Calendar <= 6.7.0 - Cross-Site Request Forgery

medium

The The Events Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.7.0. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a si...

CVSS:
4.3
Affected:
up to 6.7.0
Fixed in:
6.7.1
Disclosed:
Jan 9, 2025

CVE-2025-24537 on NVD →

The Events Calendar [the-events-calendar] < 6.5.1.5

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in The Events Calendar The Events Calendar allows Cross Site Request Forgery.This issue affects The Events Calendar: from n/a through 6.5.1.4.

Affected:
up to 6.5.1.5
Fixed in:
6.5.1.5
Disclosed:
Jan 2, 2025

CVE-2024-37518 on NVD →

The Events Calendar [the-events-calendar] < 6.8.2.1

unknown

[en] The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.

Affected:
up to 6.8.2.1
Fixed in:
6.8.2.1
Disclosed:
Dec 16, 2024

CVE-2024-5333 on NVD →

The Events Calendar [the-events-calendar] < 6.1.3

unknown

[en] Missing Authorization vulnerability in The Events Calendar The Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through 6.1.2.2.

Affected:
up to 6.1.3
Fixed in:
6.1.3
Disclosed:
Dec 13, 2024

CVE-2023-35777 on NVD →

The Events Calendar <= 6.8.2 - Missing Authorization to Unauthenticated Password Protected Event Disclosure

medium

The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.8.2 via the /wp-json/tribe/events/v1/events/ REST API due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from pass...

CVSS:
5.3
Affected:
up to 6.8.2
Fixed in:
6.8.2.1
Disclosed:
Nov 25, 2024

CVE-2024-5333 on NVD →

The Events Calendar [the-events-calendar] < 5.14.0.4

unknown

[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....

Affected:
up to 5.14.0.4
Fixed in:
5.14.0.4
Disclosed:
Oct 16, 2024

CVE-2022-4974 on NVD →

The Events Calendar [the-events-calendar] < 6.6.4

unknown

[en] The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wi...

Affected:
up to 6.6.4
Fixed in:
6.6.4
Disclosed:
Sep 27, 2024

CVE-2024-6931 on NVD →

The Events Calendar [the-events-calendar] < 6.6.4.1

unknown

[en] The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This ma...

Affected:
up to 6.6.4.1
Fixed in:
6.6.4.1
Disclosed:
Sep 25, 2024

CVE-2024-8275 on NVD →

The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection

critical

The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes i...

CVSS:
9.8
Affected:
up to 6.6.4
Fixed in:
6.6.4.1
Disclosed:
Sep 24, 2024

CVE-2024-8275 on NVD →

The Events Calendar <= 6.6.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inje...

CVSS:
4.4
Affected:
up to 6.6.3
Fixed in:
6.6.4
Disclosed:
Jul 31, 2024

CVE-2024-8493 on NVD →

The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site Scripting

high

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will ex...

CVSS:
7.2
Affected:
up to 6.6.3
Fixed in:
6.6.4
Disclosed:
Jul 23, 2024

CVE-2024-6931 on NVD →

The Events Calendar <= 6.5.1.4 - Cross-Site Request Forgery via action_restore_events

medium

The The Events Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.5.1.4. This is due to missing or incorrect nonce validation on the action_restore_events() function. This makes it possible for unauthenticated attackers to restore events via a forged request gr...

CVSS:
4.3
Affected:
up to 6.5.1.4
Fixed in:
6.5.1.5
Disclosed:
Jul 5, 2024

CVE-2024-37518 on NVD →

The Events Calendar [the-events-calendar] < 6.4.0.1

unknown

[en] The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldn't have access to. (e.g. password-protected events, drafts, etc.)

Affected:
up to 6.4.0.1
Fixed in:
6.4.0.1
Disclosed:
Jun 14, 2024

CVE-2024-1295 on NVD →

The Events Calendar [the-events-calendar] < 6.4.0.1

unknown

[en] The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.

Affected:
up to 6.4.0.1
Fixed in:
6.4.0.1
Disclosed:
Jun 4, 2024

CVE-2024-4180 on NVD →

The Events Calendar Free & Pro <= 6.4.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Events Access

medium

Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access of data due to a insufficient capability checks and restrictions on a function in various versions. This makes it possible for authenticated attackers, with Contributor-level access and above, to access arbitrary events that they should...

CVSS:
4.3
Affected:
up to 6.4.0
Fixed in:
6.4.0.1
Disclosed:
May 24, 2024

CVE-2024-1295 on NVD →

The Events Calendar <= 6.4.0 - Reflected Cross-Site Scripting

medium

The The Events Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view_data' parameter in all versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.1
Affected:
up to 6.4.0
Fixed in:
6.4.0.1
Disclosed:
May 14, 2024

CVE-2024-4180 on NVD →

The Events Calendar [the-events-calendar] < 6.3.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in The Events Calendar.This issue affects The Events Calendar: from n/a through 6.3.0.

Affected:
up to 6.3.1
Fixed in:
6.3.1
Disclosed:
Apr 15, 2024

CVE-2024-31433 on NVD →

The Events Calendar <= 6.3.0 - Cross-Site Request Forgery to Notice Dismissal

medium

The The Events Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.3.0. This is due to missing or incorrect nonce validation on the maybe_dismiss() function. This makes it possible for unauthenticated attackers to dismiss notices via a forged request granted the...

CVSS:
4.3
Affected:
up to 6.3.0
Fixed in:
6.3.1
Disclosed:
Apr 10, 2024

CVE-2024-31433 on NVD →

The Events Calendar [the-events-calendar] < 6.2.9

unknown

[en] The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it possible for unauthenticated attackers to extract potentially sensitive data including post titl...

Affected:
up to 6.2.9
Fixed in:
6.2.9
Disclosed:
Feb 5, 2024

CVE-2023-6557 on NVD →

The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposure

medium

The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it possible for unauthenticated attackers to extract potentially sensitive data including post titles an...

CVSS:
5.3
Affected:
up to 6.2.8.2
Fixed in:
6.2.9
Disclosed:
Jan 12, 2024

CVE-2023-6557 on NVD →

The Events Calendar [the-events-calendar] < 6.2.8.1

unknown

[en] The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request

Affected:
up to 6.2.8.1
Fixed in:
6.2.8.1
Disclosed:
Dec 18, 2023

CVE-2023-6203 on NVD →

The Events Calendar [the-events-calendar] < 6.2.8.1

unknown

Update the WordPress Event Single Page Templates Addon For The Events Calendar plugin to the latest available version (at least 6.2.8.1). Unknown discovered and reported this Sensitive Data Exposure vulnerability in WordPress The Events Calendar Plugin. This vulnerability has been fixed in version 6.2.8.1.

Affected:
up to 6.2.8.1
Fixed in:
6.2.8.1
Disclosed:
Nov 22, 2023

The Events Calendar <= 6.2.8 - Information Disclosure

medium

The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.2.8 via the get_data function. This makes it possible for unauthenticated attackers to extract sensitive data including private post content, via the REST API.

CVSS:
5.3
Affected:
up to 6.2.8.1
Fixed in:
6.2.8.1
Disclosed:
Nov 20, 2023

CVE-2023-6203 on NVD →

The Events Calendar [the-events-calendar] < 6.2.8.1

unknown

The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.2.8 via the get_data function. This makes it possible for unauthenticated attackers to extract sensitive data including private post content, via the REST API.

Affected:
up to 6.2.8.1
Fixed in:
6.2.8.1
Disclosed:
Nov 20, 2023

The Events Calendar [the-events-calendar] < 3.0.1

unknown

Update the plugin. An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress The Events Calendar Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when gue...

Affected:
up to 3.0.1
Fixed in:
3.0.1
Disclosed:
Aug 1, 2023

The Events Calendar <= 6.1.2.2 - Missing Authorization

medium

The The Events Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_ical_output_for_an_event() function in versions up to, and including, 6.1.2.2. This makes it possible for unauthenticated attackers to view arbitrary/private event content.

CVSS:
4.3
Affected:
up to 6.1.2.2
Fixed in:
6.1.3
Disclosed:
Jul 25, 2023

CVE-2023-35777 on NVD →

Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get

medium

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
4.9.0 – 5.16.4
Fixed in:
5.16.4.1
Disclosed:
Jul 18, 2023

CVE-2023-33999 on NVD →

The Events Calendar [the-events-calendar] < 4.1.1.1

unknown

Update the plugin. Paul Mynarsky discovered and reported this Open Redirection vulnerability in WordPress The Events Calendar Plugin. This could allow a malicious actor to redirect users from one site to the other due to the redirect URL not being validated. Users could be tricked to visiting a legitimate site to then...

Affected:
up to 4.1.1.1
Fixed in:
4.1.1.1
Disclosed:
Apr 25, 2023

The Events Calendar [the-events-calendar] < 5.14.0.4

unknown

Update the WordPress The Events Calendar plugin to the latest available version (at least 5.14.0.4). An unknown person discovered and reported this Sensitive Data Exposure vulnerability in WordPress The Events Calendar Plugin. This vulnerability has been fixed in version 5.14.0.4.

Affected:
up to 5.14.0.4
Fixed in:
5.14.0.4
Disclosed:
Feb 28, 2023

The Events Calendar [the-events-calendar] < 5.14.0.4

unknown

Update the WordPress The Events Calendar plugin to the latest available version (at least 5.14.0.4). An unknown person discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress The Events Calendar Plugin. This could allow a malicious actor to force higher privileged users to execute unwa...

Affected:
up to 5.14.0.4
Fixed in:
5.14.0.4
Disclosed:
Feb 28, 2023

Freemius SDK <= 2.4.2 - Missing Authorization Checks

medium

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

CVSS:
6.3
Affected:
up to 5.14.0.4
Fixed in:
5.14.0.4
Disclosed:
Mar 4, 2022

CVE-2022-4974 on NVD →

The Events Calendar [the-events-calendar] < 5.14.0.4

unknown

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

Affected:
up to 5.14.0.4
Fixed in:
5.14.0.4
Disclosed:
Mar 4, 2022

The Events Calendar [the-events-calendar] < 5.14.0.4

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress The Events Calendar plugin (versions < 5.14.0.4).

Affected:
up to 5.14.0.4
Fixed in:
5.14.0.4
Disclosed:
Feb 28, 2022

The Events Calendar [the-events-calendar] < 5.14.0.4

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress The Events Calendar plugin (versions < 5.14.0.4).

Affected:
up to 5.14.0.4
Fixed in:
5.14.0.4
Disclosed:
Feb 28, 2022

The Events Calendar [the-events-calendar] < 4.8.2

unknown

[en] The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.

Affected:
up to 4.8.2
Fixed in:
4.8.2
Disclosed:
Aug 21, 2019

CVE-2019-15109 on NVD →

The Events Calendar <= 4.8.1 - Cross-Site Scripting via tribe_paged Parameter

medium

The Events Calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.

CVSS:
6.1
Affected:
up to 4.8.2
Fixed in:
4.8.2
Disclosed:
Mar 4, 2019

CVE-2019-15109 on NVD →

The Events Calendar < 4.1.1.1 - Open Redirect

medium

The Events Calendar plugin for WordPress is vulnerable to an open redirect vulnerability in versions before 4.1.1.1. This allows attackers to redirect victims to an untrusted site via a crafted link on a vulnerable trusted site.

CVSS:
4.7
Affected:
up to 4.1.1
Fixed in:
4.1.1.1
Disclosed:
Apr 25, 2016

The Events Calendar [the-events-calendar] < 4.1.1.1

unknown

The Events Calendar plugin for WordPress is vulnerable to an open redirect vulnerability in versions before 4.1.1.1. This allows attackers to redirect victims to an untrusted site via a crafted link on a vulnerable trusted site.

Affected:
up to 4.1.1.1
Fixed in:
4.1.1.1
Disclosed:
Apr 25, 2016

The Events Calendar [the-events-calendar] < 4.1.1.1

unknown

This plugin is prone to an open redirection vulnerability in the "tribe-bar-view" parameter. Update the plugin.

Affected:
up to 4.1.1.1
Fixed in:
4.1.1.1
Disclosed:
Apr 25, 2016

The Events Calendar [the-events-calendar] < 3.0.1

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 3.0.1
Fixed in:
3.0.1
Disclosed:
Aug 1, 2014

The Events Calendar [the-events-calendar] < 6.13.2.1

unknown
Affected:
up to 6.13.2.1
Fixed in:
6.13.2.1

CVE-2025-5144 on NVD →

The Events Calendar [the-events-calendar] < 6.6.4

unknown
Affected:
up to 6.6.4
Fixed in:
6.6.4

CVE-2024-8493 on NVD →

The Events Calendar [the-events-calendar] < 5.14.0

unknown

The plugin does not escape an aggregator URL before outputting it back in an attribute, leading to Reflected Cross-Site Scripting

Affected:
up to 5.14.0
Fixed in:
5.14.0

The Events Calendar [the-events-calendar] < 3.0.1

unknown

The The Events Calendar WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 3.0.1
Fixed in:
3.0.1

The Events Calendar [the-events-calendar] < 4.1.1.1

unknown

The problem is located in the &quot;tribe-bar-view&quot; parameter that can be used to redirect a user to an arbitrary website. Timeline * 2016-04-04 : Initial contact with Modern Tribe * 2016-04-05 : Modern Tribe confirms the report * 2016-04-07 : Modern Tribe publishes a new version (4.1.1.1) that resolves th...

Affected:
up to 4.1.1.1
Fixed in:
4.1.1.1

The Events Calendar [the-events-calendar] < 6.1.0

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 6.1.0
Fixed in:
6.1.0

CVE-2023-33999 on NVD →

The Events Calendar [the-events-calendar] < 5.14.0.4

unknown

The plugins and themes use an insecure version of the Freemius Framework, which is lacking CSRF and/or authorisation in some of its AJAX actions. As a result, any authenticated users, such as subscriber could access the debug logs. Unauthenticated attackers could also make a logged in admin toggle the debug mode via a...

Affected:
up to 5.14.0.4
Fixed in:
5.14.0.4

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database