Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

The Events Calendar — Vulnerabilities & Security Advisories 35

All 35 CVE vulnerabilities found in The Events Calendar, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security advisories for The Events Calendar, focusing on the WordPress plugin by The Events Calendar, Inc. It collects documented software vulnerabilities, categorized by weakness type such as cross-site scripting, privilege escalation, and remote code execution, spanning the plugin's active support window from its initial release through recent major version updates. Visitors can track The Events Calendar, Inc. advisories, analyze the impact of a specific vulnerability class on event management systems, and review the complete vulnerability history of The Events Calendar to identify recurring attack vectors and remediation trends across versions.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-95606 WordPress The Events Calendar plugin <= 6.17.4 - PHP Object Injection vulnerability CWE-502 9.8 Critical 2026-10-07
CVE-2026-84740 The Events Calendar 6.12.0 - 6.17.5 - Unauthenticated Arbitrary Shortcode Execution via 'view_data' Parameter 6.5 Medium 2026-10-02
CVE-2026-97285 WordPress The Events Calendar plugin <= 6.17.5 - Broken Access Control vulnerability CWE-862 5.4 Medium 2026-09-30
CVE-2026-84742 The Events Calendar 6.15.0 - 6.17.4.1 - Contributor+ Content Publication via TEC V1 REST API - - 2026-09-23
CVE-2026-84743 The Events Calendar 6.15.16.1 - 6.17.4.1 - Contributor+ Event/Venue/Organizer Update, Trash and Ownership Takeover via by-slug REST Routes - - 2026-09-23
CVE-2026-84741 The Events Calendar 4.5 - 6.17.4.1 - Unauthenticated Non-Public Venue and Organizer Disclosure via REST API - - 2026-09-23
CVE-2026-78159 The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation CWE-94 9.8 Critical 2026-09-12
CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution CWE-502 9.8 Critical 2026-09-12
CVE-2026-84745 The Events Calendar &lt; 6.17.3.1 - Contributor+ Non-Public Event, Venue and Organizer Content Disclosure via REST API - - 2026-09-05
CVE-2026-78265 WordPress The Events Calendar plugin <= 6.17.2 - PHP Object Injection vulnerability CWE-502 9.8 Critical 2026-08-24
CVE-2026-13390 The Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Status Manipulation - - 2026-07-27
CVE-2026-49772 WordPress The Events Calendar plugin 6.15.12-6.16.2 - SQL Injection vulnerability CWE-89 9.3 Critical 2026-06-16
CVE-2026-3585 The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_import CWE-22 7.5 High 2026-03-10
CVE-2026-2694 The Events Calendar <= 6.15.16 - Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API CWE-285 5.4 Medium 2026-02-25
CVE-2025-15043 The Events Calendar <= 6.15.13 - Missing Authorization to Authenticated (Subscriber+) Data Migration Control CWE-862 5.4 Medium 2026-01-20
CVE-2025-69352 WordPress The Events Calendar plugin <= 6.15.12.2 - Broken Access Control vulnerability CWE-862 5.4 Medium 2026-01-06
CVE-2025-12192 The Events Calendar <= 6.15.9 - Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information Exposure CWE-697 5.3 Medium 2025-11-05
CVE-2025-12197 The Events Calendar 6.15.1.1 - 6.15.9 - Unauthenticated SQL Injection via s CWE-89 7.5 High 2025-11-05
CVE-2025-12175 The Events Calendar <= 6.15.9 - Missing Authorization to Authenticated (Subscriber+) Draft Event Title/QR Code Exposure CWE-862 4.3 Medium 2025-10-31
CVE-2025-9808 The Events Calendar <= 6.15.2 - Missing Authorization to Unauthenticated Password-Protected Information Disclosure CWE-200 5.3 Medium 2025-09-16
CVE-2025-9807 The Events Calendar <= 6.15.1 - Unauthenticated SQL Injection CWE-89 7.5 High 2025-09-12
CVE-2025-5144 The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting CWE-79 6.4 Medium 2025-06-11
CVE-2025-48246 WordPress The Events Calendar plugin <= 6.11.2.1 - Broken Access Control Vulnerability CWE-862 5.4 Medium 2025-05-19
CVE-2024-8493 The Events Calendar < 6.6.4 - Admin+ Stored XSS 4.8AI Medium AI 2025-05-15
CVE-2025-24537 WordPress The Events Calendar plugin <= 6.7.0 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 5.4 Medium 2025-01-27
CVE-2024-12118 The Events Calendar <= 6.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2025-01-23
CVE-2024-37518 WordPress The Events Calendar plugin <= 6.5.1.4 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 4.3 Medium 2025-01-02
CVE-2024-5333 The Events Calendar < 6.8.2.1 - Unauthenticated Password Protected Event Disclosure 5.3 - 2024-12-16
CVE-2023-35777 WordPress The Events Calendar plugin <= 6.1.2.2 - Broken Access Control vulnerability CWE-862 5.3 Medium 2024-12-13
CVE-2024-6931 The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site Scripting CWE-79 7.2 High 2024-09-27

All 35 known CVE vulnerabilities affecting The Events Calendar with full Chinese analysis, references, and POCs where available.