stellarwp records
10 published records for vendor stellarwp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-287 Improper Authentication1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-862 Missing Authorization1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
54Plan | CVE-2024-8275Proof of concept | The Events Calendar <= 6.6.4 - Unauthenticated SQL Injectionstellarwp · the events calendar · CWE-89 | Critical9.8 | — | 49.9% | Sep 25, 2024 |
37Monitor | CVE-2024-4180Proof of concept | The Events Calendar < 6.4.0.1 - Reflected XSSstellarwp · the events calendar · CWE-79 | Critical9.1 | — | 1.8% | Jun 4, 2024 |
30Monitor | CVE-2023-6203No exploit | The Events Calendar < 6.2.8.1 - Unauthenticated Arbitrary Password Protected Post Readstellarwp · the events calendar · CWE-287 | High7.5 | — | 0.8% | Dec 18, 2023 |
29Monitor | CVE-2024-6931No exploit | The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site Scriptingstellarwp · the events calendar · CWE-79 | Medium6.1 | — | 16.7% | Sep 27, 2024 |
24Monitor | CVE-2019-15109No exploit | The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.stellarwp · the events calendar · CWE-79 | Medium6.1 | — | 1.1% | Aug 21, 2019 |
21Monitor | CVE-2024-5333Proof of concept | The Events Calendar < 6.8.2.1 - Unauthenticated Password Protected Event Disclosurestellarwp · the events calendar · CWE-639 | Medium5.3 | — | 1.1% | Dec 16, 2024 |
21Monitor | CVE-2023-6557No exploit | The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposurestellarwp · the events calendar · CWE-862 | Medium5.3 | — | 0.6% | Feb 5, 2024 |
21Monitor | CVE-2025-5144No exploit | The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scriptingstellarwp · the events calendar · CWE-79 | Medium5.4 | — | 0.3% | Jun 11, 2025 |
19Monitor | CVE-2024-8493No exploit | The Events Calendar < 6.6.4 - Admin+ Stored XSSstellarwp · the events calendar · CWE-79 | Medium4.8 | — | 0.3% | May 15, 2025 |
19Monitor | CVE-2024-10939No exploit | Image Widget < 4.4.11 - Admin+ Stored XSSstellarwp · image widget · CWE-79 | Medium4.8 | — | 0.3% | Dec 13, 2024 |
- CVE-2024-827554Plan
The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection
CriticalCVSS 9.8Proof of conceptEPSS 50%stellarwp · the events calendarSep 25, 2024
- CVE-2024-418037Monitor
The Events Calendar < 6.4.0.1 - Reflected XSS
CriticalCVSS 9.1Proof of conceptEPSS 2%stellarwp · the events calendarJun 4, 2024
- CVE-2023-620330Monitor
The Events Calendar < 6.2.8.1 - Unauthenticated Arbitrary Password Protected Post Read
HighCVSS 7.5No exploitEPSS 1%stellarwp · the events calendarDec 18, 2023
- CVE-2024-693129Monitor
The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 17%stellarwp · the events calendarSep 27, 2024
- CVE-2019-1510924Monitor
The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.
MediumCVSS 6.1No exploitEPSS 1%stellarwp · the events calendarAug 21, 2019
- CVE-2024-533321Monitor
The Events Calendar < 6.8.2.1 - Unauthenticated Password Protected Event Disclosure
MediumCVSS 5.3Proof of conceptEPSS 1%stellarwp · the events calendarDec 16, 2024
- CVE-2023-655721Monitor
The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposure
MediumCVSS 5.3No exploitEPSS 1%stellarwp · the events calendarFeb 5, 2024
- CVE-2025-514421Monitor
The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%stellarwp · the events calendarJun 11, 2025
- CVE-2024-849319Monitor
The Events Calendar < 6.6.4 - Admin+ Stored XSS
MediumCVSS 4.8No exploitEPSS 0%stellarwp · the events calendarMay 15, 2025
- CVE-2024-1093919Monitor
Image Widget < 4.4.11 - Admin+ Stored XSS
MediumCVSS 4.8No exploitEPSS 0%stellarwp · image widgetDec 13, 2024