Skip to content
Noroxi

stellarwp records

10 published records for vendor stellarwp.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
50%
Median publish → KEV
No record has entered KEV

All records

10 records
  • The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection

    CriticalCVSS 9.8Proof of conceptEPSS 50%

    stellarwp · the events calendarSep 25, 2024

  • CVE-2024-4180
    37Monitor

    The Events Calendar < 6.4.0.1 - Reflected XSS

    CriticalCVSS 9.1Proof of conceptEPSS 2%

    stellarwp · the events calendarJun 4, 2024

  • CVE-2023-6203
    30Monitor

    The Events Calendar < 6.2.8.1 - Unauthenticated Arbitrary Password Protected Post Read

    HighCVSS 7.5No exploitEPSS 1%

    stellarwp · the events calendarDec 18, 2023

  • CVE-2024-6931
    29Monitor

    The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 17%

    stellarwp · the events calendarSep 27, 2024

  • The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.

    MediumCVSS 6.1No exploitEPSS 1%

    stellarwp · the events calendarAug 21, 2019

  • CVE-2024-5333
    21Monitor

    The Events Calendar < 6.8.2.1 - Unauthenticated Password Protected Event Disclosure

    MediumCVSS 5.3Proof of conceptEPSS 1%

    stellarwp · the events calendarDec 16, 2024

  • CVE-2023-6557
    21Monitor

    The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposure

    MediumCVSS 5.3No exploitEPSS 1%

    stellarwp · the events calendarFeb 5, 2024

  • CVE-2025-5144
    21Monitor

    The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 0%

    stellarwp · the events calendarJun 11, 2025

  • CVE-2024-8493
    19Monitor

    The Events Calendar < 6.6.4 - Admin+ Stored XSS

    MediumCVSS 4.8No exploitEPSS 0%

    stellarwp · the events calendarMay 15, 2025

  • Image Widget < 4.4.11 - Admin+ Stored XSS

    MediumCVSS 4.8No exploitEPSS 0%

    stellarwp · image widgetDec 13, 2024