Skip to content
Noroxi

The Events Calendar

the-events-calendar · plugin

Known security vulnerabilities for The Events Calendar. Find out in seconds which version runs on your site with WP Lens.

24 known vulnerabilities

5 critical · 15 exploitable without logging in · 4 with public exploit code · latest Sep 30, 2026

Listed on wordpress.org · latest 6.18.0 · last updated Sep 30, 2026 · 600K+ installs

wordpress.org status checked on Oct 4, 2026

Vulnerabilities

  • CVE-2026-78159unauthenticated≤ 6.17.3

    The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation

    Critical 9.8
  • CVE-2026-78006unauthenticated≤ 6.17.4

    The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

    Critical 9.8
  • CVE-2026-78265unauthenticated≤ 6.17.2

    WordPress The Events Calendar plugin <= 6.17.2 - PHP Object Injection vulnerability

    Critical 9.8
  • CVE-2024-8275unauthenticated≤ 6.6.4

    The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection

    Critical 9.8
  • CVE-2026-49772unauthenticated≤ 6.16.2

    WordPress The Events Calendar plugin 6.15.12-6.16.2 - SQL Injection vulnerability

    Critical 9.3
  • CVE-2025-12197unauthenticated≤ 6.15.9

    The Events Calendar 6.15.1.1 - 6.15.9 - Unauthenticated SQL Injection via s

    High 7.5
  • CVE-2025-9807unauthenticated≤ 6.15.1

    The Events Calendar <= 6.15.1 - Unauthenticated SQL Injection

    High 7.5
  • CVE-2026-3585author+≤ 6.15.17

    The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_import

    High 7.5
  • CVE-2024-6931unauthenticated≤ 6.6.3

    The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site Scripting

    Medium 6.1
  • CVE-2019-15109unauthenticated · needs a click

    The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.

    Medium 6.1
  • CVE-2025-24537unauthenticated · needs a click≤ 6.7.0

    WordPress The Events Calendar plugin <= 6.7.0 - Cross Site Request Forgery (CSRF) vulnerability

    Medium 5.4
  • CVE-2025-15043subscriber+≤ 6.15.13

    The Events Calendar <= 6.15.13 - Missing Authorization to Authenticated (Subscriber+) Data Migration Control

    Medium 5.4
  • CVE-2025-69352login required≤ 6.15.12.2

    WordPress The Events Calendar plugin <= 6.15.12.2 - Broken Access Control vulnerability

    Medium 5.4
  • CVE-2025-48246login required≤ 6.11.2.1

    WordPress The Events Calendar plugin <= 6.11.2.1 - Broken Access Control Vulnerability

    Medium 5.4
  • CVE-2026-97285contributor+≤ 6.17.5

    WordPress The Events Calendar plugin <= 6.17.5 - Broken Access Control vulnerability

    Medium 5.4
  • CVE-2026-2694contributor+≤ 6.15.16

    The Events Calendar <= 6.15.16 - Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API

    Medium 5.4
  • CVE-2025-5144contributor+≤ 6.13.2

    The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

    Medium 5.4
  • CVE-2024-12118contributor+≤ 6.9.0

    The Events Calendar <= 6.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

    Medium 5.4
  • CVE-2025-12192unauthenticated≤ 6.15.9

    The Events Calendar <= 6.15.9 - Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information Exposure

    Medium 5.3
  • CVE-2023-35777unauthenticated≤ 6.1.2.2

    WordPress The Events Calendar plugin <= 6.1.2.2 - Broken Access Control vulnerability

    Medium 5.3
  • CVE-2023-6557unauthenticated≤ 6.2.8.2

    The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposure

    Medium 5.3
  • CVE-2024-37518unauthenticated · needs a click≤ 6.5.1.4

    WordPress The Events Calendar plugin <= 6.5.1.4 - Cross Site Request Forgery (CSRF) vulnerability

    Medium 4.3
  • CVE-2024-31433unauthenticated · needs a click≤ 6.3.0

    WordPress The Events Calendar plugin <= 6.3.0 - Cross Site Request Forgery (CSRF) vulnerability

    Medium 4.3
  • CVE-2025-12175subscriber+≤ 6.15.9

    The Events Calendar <= 6.15.9 - Missing Authorization to Authenticated (Subscriber+) Draft Event Title/QR Code Exposure

    Medium 4.3

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory