All 35 CVE vulnerabilities found in The Events Calendar, with AI-generated Chinese analysis, references, and POCs.
This page aggregates security advisories for The Events Calendar, focusing on the WordPress plugin by The Events Calendar, Inc. It collects documented software vulnerabilities, categorized by weakness type such as cross-site scripting, privilege escalation, and remote code execution, spanning the plugin's active support window from its initial release through recent major version updates. Visitors can track The Events Calendar, Inc. advisories, analyze the impact of a specific vulnerability class on event management systems, and review the complete vulnerability history of The Events Calendar to identify recurring attack vectors and remediation trends across versions.
Vendor: Unknown
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-8275 | The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection CWE-89 | 9.8 | Critical | 2024-09-25 |
| CVE-2024-4180 | The Events Calendar < 6.4.0.1 - Reflected XSS | 6.1AI | Medium AI | 2024-06-04 |
| CVE-2024-31433 | WordPress The Events Calendar plugin <= 6.3.0 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 | 4.3 | Medium | 2024-04-15 |
| CVE-2023-6557 | The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposure CWE-862 | 5.3 | Medium | 2024-02-05 |
| CVE-2023-6203 | The Events Calendar < 6.2.8.1 - Unauthenticated Arbitrary Password Protected Post Read | 7.5AI | High AI | 2023-12-18 |
All 35 known CVE vulnerabilities affecting The Events Calendar with full Chinese analysis, references, and POCs where available.