The Events Calendar
the-events-calendar · plugin
Known security vulnerabilities for The Events Calendar. Find out in seconds which version runs on your site with WP Lens.
24 known vulnerabilities
5 critical · 15 exploitable without logging in · 4 with public exploit code · latest Sep 30, 2026
Listed on wordpress.org · latest 6.18.0 · last updated Sep 30, 2026 · 600K+ installs
wordpress.org status checked on Oct 4, 2026
Vulnerabilities
- Critical 9.8
CVE-2026-78159unauthenticated≤ 6.17.3
The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation
- Critical 9.8
CVE-2026-78006unauthenticated≤ 6.17.4
The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution
- Critical 9.8
CVE-2026-78265unauthenticated≤ 6.17.2
WordPress The Events Calendar plugin <= 6.17.2 - PHP Object Injection vulnerability
- Critical 9.8
CVE-2024-8275unauthenticated≤ 6.6.4
The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection
- Critical 9.3
CVE-2026-49772unauthenticated≤ 6.16.2
WordPress The Events Calendar plugin 6.15.12-6.16.2 - SQL Injection vulnerability
- High 7.5
CVE-2025-12197unauthenticated≤ 6.15.9
The Events Calendar 6.15.1.1 - 6.15.9 - Unauthenticated SQL Injection via s
- High 7.5
CVE-2025-9807unauthenticated≤ 6.15.1
The Events Calendar <= 6.15.1 - Unauthenticated SQL Injection
- High 7.5
CVE-2026-3585author+≤ 6.15.17
The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_import
- Medium 6.1
CVE-2024-6931unauthenticated≤ 6.6.3
The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site Scripting
- Medium 6.1
CVE-2019-15109unauthenticated · needs a click
The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.
- Medium 5.4
CVE-2025-24537unauthenticated · needs a click≤ 6.7.0
WordPress The Events Calendar plugin <= 6.7.0 - Cross Site Request Forgery (CSRF) vulnerability
- Medium 5.4
CVE-2025-15043subscriber+≤ 6.15.13
The Events Calendar <= 6.15.13 - Missing Authorization to Authenticated (Subscriber+) Data Migration Control
- Medium 5.4
CVE-2025-69352login required≤ 6.15.12.2
WordPress The Events Calendar plugin <= 6.15.12.2 - Broken Access Control vulnerability
- Medium 5.4
CVE-2025-48246login required≤ 6.11.2.1
WordPress The Events Calendar plugin <= 6.11.2.1 - Broken Access Control Vulnerability
- Medium 5.4
CVE-2026-97285contributor+≤ 6.17.5
WordPress The Events Calendar plugin <= 6.17.5 - Broken Access Control vulnerability
- Medium 5.4
CVE-2026-2694contributor+≤ 6.15.16
The Events Calendar <= 6.15.16 - Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API
- Medium 5.4
CVE-2025-5144contributor+≤ 6.13.2
The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
- Medium 5.4
CVE-2024-12118contributor+≤ 6.9.0
The Events Calendar <= 6.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
- Medium 5.3
CVE-2025-12192unauthenticated≤ 6.15.9
The Events Calendar <= 6.15.9 - Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information Exposure
- Medium 5.3
CVE-2023-35777unauthenticated≤ 6.1.2.2
WordPress The Events Calendar plugin <= 6.1.2.2 - Broken Access Control vulnerability
- Medium 5.3
CVE-2023-6557unauthenticated≤ 6.2.8.2
The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposure
- Medium 4.3
CVE-2024-37518unauthenticated · needs a click≤ 6.5.1.4
WordPress The Events Calendar plugin <= 6.5.1.4 - Cross Site Request Forgery (CSRF) vulnerability
- Medium 4.3
CVE-2024-31433unauthenticated · needs a click≤ 6.3.0
WordPress The Events Calendar plugin <= 6.3.0 - Cross Site Request Forgery (CSRF) vulnerability
- Medium 4.3
CVE-2025-12175subscriber+≤ 6.15.9
The Events Calendar <= 6.15.9 - Missing Authorization to Authenticated (Subscriber+) Draft Event Title/QR Code Exposure
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).