HomeWordPress vulnerabilitiesThe Events Calendar
The Events Calendar vulnerabilities
The Events Calendar has 22 known vulnerabilities in this database. The most recent published record is dated 7 Oct 2026.
- Known vulnerabilities
- 22
- Active installs
- 600,000+
- Latest version
- 6.18.0
- Last updated
- 30 Sep 2026
- Most recent
- 7 Oct 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| PHP object injection CVE-2026-95606 | Critical 9.8 | Up to 6.17.4 | Fixed in a later version (latest 6.18.0) | 6 h ago |
| Remote code execution CVE-2026-78006 | Critical 9.8 | Up to 6.17.4 | Fixed in a later version (latest 6.18.0) | 12 Sep 2026 |
| Remote code execution CVE-2026-78159 | Critical 9.8 | Up to 6.17.3 | Fixed in a later version (latest 6.18.0) | 12 Sep 2026 |
| Path traversal CVE-2026-3585 | High 7.5 | Up to 6.15.17 | Fixed in a later version (latest 6.18.0) | 10 Mar 2026 |
| Broken access control CVE-2026-2694 | Medium 5.4 | Up to 6.15.16 | Fixed in a later version (latest 6.18.0) | 25 Feb 2026 |
| Broken access control CVE-2025-15043 | Medium 5.4 | Up to 6.15.13 | Fixed in a later version (latest 6.18.0) | 20 Jan 2026 |
| Sensitive data exposure CVE-2025-12192 | Medium 5.3 | Up to 6.15.9 | Fixed in a later version (latest 6.18.0) | 5 Nov 2025 |
| SQL injection CVE-2025-12197 | High 7.5 | Not yet published | Check for an update | 5 Nov 2025 |
| Broken access control CVE-2025-12175 | Medium 4.3 | Up to 6.15.9 | Fixed in a later version (latest 6.18.0) | 31 Oct 2025 |
| Sensitive data exposure CVE-2025-9808 | Medium 5.3 | Up to 6.15.2 | Fixed in a later version (latest 6.18.0) | 16 Sep 2025 |
| SQL injection CVE-2025-9807 | High 7.5 | Up to 6.15.1 | Fixed in a later version (latest 6.18.0) | 12 Sep 2025 |
| Cross-site scripting (XSS) CVE-2025-5144 | Medium 6.4 | Before 6.13.2.1 | Fixed in 6.13.2.1 | 11 Jun 2025 |
| Cross-site scripting (XSS) CVE-2024-8493 | Medium 4.8 | Before 6.6.4 | Fixed in 6.6.4 | 15 May 2025 |
| Cross-site scripting (XSS) CVE-2024-12118 | Medium 6.4 | Before 6.9.1 | Fixed in 6.9.1 | 23 Jan 2025 |
| Security weakness CVE-2024-5333 | Medium 5.3 | Before 6.8.2.1 | Fixed in 6.8.2.1 | 16 Dec 2024 |
| Cross-site scripting (XSS) CVE-2024-6931 | High 7.2 | Before 6.6.4 | Fixed in 6.6.4 | 27 Sep 2024 |
| SQL injection CVE-2024-8275 | Critical 9.8 | Before 6.6.4.1 | Fixed in 6.6.4.1 | 25 Sep 2024 |
| Security weakness CVE-2024-1295 | Medium 6.5 | Before 6.4.0.1 | Fixed in 6.4.0.1 | 14 Jun 2024 |
| Cross-site scripting (XSS) CVE-2024-4180 | Critical 9.1 | Before 6.4.0.1 | Fixed in 6.4.0.1 | 4 Jun 2024 |
| Sensitive data exposure CVE-2023-6557 | Medium 5.3 | Up to 6.2.8.2 | Fixed in a later version (latest 6.18.0) | 5 Feb 2024 |
| Security weakness CVE-2023-6203 | High 7.5 | Before 6.2.8.1 | Fixed in 6.2.8.1 | 18 Dec 2023 |
| Cross-site scripting (XSS) CVE-2019-15109 | Medium 6.1 | Before 4.8.2 | Fixed in 4.8.2 | 21 Aug 2019 |
Read the published descriptions
- CVE-2026-95606, 7 Oct 2026
- Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection. This issue affects The Events Calendar: from n/a through 6.17.4. CVE record
- CVE-2026-78006, 12 Sep 2026
- The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attribute before unserialize() is reached. This makes it possible for unauthenticated attackers to execute code on the server. This is exploitable without authentication or approval because the plugin's V2 single-event template runs do_blocks() over buffered comment HTML, and WordPress returns a moderation-hash URL that allows an unauthenticated commenter to immediately view their own pending comment, delivering the injected block markup to the vulnerable code path before any moderation occurs. This does require comments to be enabled and visible on events. CVE record
- CVE-2026-78159, 12 Sep 2026
- The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the targeted site has comments enabled on tribe_events posts and that at least one comment containing a crafted wp:legacy-widget block has been submitted, as the attack chain is triggered when do_blocks() processes the single-event HTML including the comment area. CVE record
- CVE-2026-3585, 10 Mar 2026
- The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.17 via the 'ajax_create_import' function. This makes it possible for authenticated attackers, with Author-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. CVE record
- CVE-2026-2694, 25 Feb 2026
- The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to an improper capability check on the 'can_edit' and 'can_delete' function in all versions up to, and including, 6.15.16. This makes it possible for authenticated attackers, with Contributor-level access and above, to update or trash events, organizers and venues via REST API. CVE record
- CVE-2025-15043, 20 Jan 2026
- The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'start_migration', 'cancel_migration', and 'revert_migration' functions in all versions up to, and including, 6.15.13. This makes it possible for authenticated attackers, with subscriber level access and above, to start, cancel, or revert the Custom Tables V1 database migration, including dropping the custom database tables entirely via the revert action. CVE record
- CVE-2025-12192, 5 Nov 2025
- The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.9. The sysinfo REST endpoint compares the provided key to the stored opt-in key using a loose comparison, allowing unauthenticated attackers to send a boolean value and obtain the full system report whenever "Yes, automatically share my system information with The Events Calendar support team" setting is enabled. CVE record
- CVE-2025-12197, 5 Nov 2025
- The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15.1.1 to 6.15.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2025-12175, 31 Oct 2025
- The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'tec_qr_code_modal' AJAX endpoint in all versions up to, and including, 6.15.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view draft event names and generate/view QR codes for them. CVE record
- CVE-2025-9808, 16 Sep 2025
- The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract information about password-protected vendors or venues. CVE record
- CVE-2025-9807, 12 Sep 2025
- The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all versions up to, and including, 6.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2025-5144, 11 Jun 2025
- The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, 6.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-8493, 15 May 2025
- The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
- CVE-2024-12118, 23 Jan 2025
- The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget through the html_tag attribute in all versions up to, and including, 6.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-5333, 16 Dec 2024
- The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events. CVE record
- CVE-2024-6931, 27 Sep 2024
- The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-8275, 25 Sep 2024
- The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Only sites that have manually added tribe_has_next_event() will be vulnerable to this SQL injection. CVE record
- CVE-2024-1295, 14 Jun 2024
- The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldn't have access to. (e.g. password-protected events, drafts, etc.) CVE record
- CVE-2024-4180, 4 Jun 2024
- The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX. CVE record
- CVE-2023-6557, 5 Feb 2024
- The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it possible for unauthenticated attackers to extract potentially sensitive data including post titles and IDs of pending, private and draft posts. CVE record
- CVE-2023-6203, 18 Dec 2023
- The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request CVE record
- CVE-2019-15109, 21 Aug 2019
- The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter. CVE record
What to do if you run The Events Calendar
If you run The Events Calendar, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new The Events Calendar vulnerabilities
Free. We email you when a new vulnerability is published for The Events Calendar, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.