Vulnerabilities
10 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-5144 | The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, 6.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2024-8493 | The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to per The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2024-5333 | The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about pas The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events. NVD description · AI analysis pending | 5.3 | 1% | PoC |
| — | |
| CVE-2024-10939 | The Image Widget WordPress plugin before 4.4.11 does not sanitise and escape some of its Image Widget settings, which could allow high privilege users such as a The Image Widget WordPress plugin before 4.4.11 does not sanitise and escape some of its Image Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2024-6931 | The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6.6.3 due to The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD description · AI analysis pending | 6.1 | 17% |
| — | ||
| CVE-2024-8275 | Unauthenticated SQL Injection in The Events Calendar WordPress Plugin CVE-2024-8275 is a critical SQL injection (CWE-89) in The Events Calendar WordPress plugin from StellarWP, caused by insufficient escaping of the user-supplied 'order' parameter in the tribe_has_next_event() function and inadequate preparation of the underlying SQL query. An unauthenticated attacker can append additional SQL queries to existing ones over the network without any privileges or user interaction, allowing extraction of sensitive information from the site's database. Only WordPress sites running The Events Calendar version 6.6.4 or earlier where the site owner has manually added calls to tribe_has_next_event() (for example in custom templates) are vulnerable. There are no known public proof-of-concept exploits, it is not yet in CISA's KEV catalog, and no confirmed in-the-wild exploitation is known, but EPSS assigns a high ~49.9% probability of exploitation within 30 days. Do: Update The Events Calendar to a version later than 6.6.4 (the first release after 6.6.4). Site owners should search their themes, custom templates, and snippet plugins for calls to tribe_has_next_event(); if the function is not used, the site is not exploitable. As an interim mitigation, apply a WAF rule blocking SQL injection patterns in the 'order' parameter. | 9.8 | 50% |
| largelikely low tens of thousands of sites out of roughly 200,000+ active installs of the plugin, since only sites with custom code calling tribe_has_next_event()… | ||
| CVE-2024-4180 | The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX. The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX. NVD description · AI analysis pending | 9.1 | 2% | PoC |
| — | |
| CVE-2023-6557 | The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route functio The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it possible for unauthenticated attackers to extract potentially sensitive data including post titles and IDs of pending, private and draft posts. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2023-6203 | The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2019-15109 | The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter. The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter. NVD description · AI analysis pending | 6.1 | 1% |
| — |