Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesThe Events Calendar

The Events Calendar vulnerabilities

The Events Calendar has 22 known vulnerabilities in this database. The most recent published record is dated 7 Oct 2026.

Known vulnerabilities
22
Active installs
600,000+
Latest version
6.18.0
Last updated
30 Sep 2026
Most recent
7 Oct 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
PHP object injection
CVE-2026-95606
Critical 9.8Up to 6.17.4Fixed in a later version (latest 6.18.0)6 h ago
Remote code execution
CVE-2026-78006
Critical 9.8Up to 6.17.4Fixed in a later version (latest 6.18.0)12 Sep 2026
Remote code execution
CVE-2026-78159
Critical 9.8Up to 6.17.3Fixed in a later version (latest 6.18.0)12 Sep 2026
Path traversal
CVE-2026-3585
High 7.5Up to 6.15.17Fixed in a later version (latest 6.18.0)10 Mar 2026
Broken access control
CVE-2026-2694
Medium 5.4Up to 6.15.16Fixed in a later version (latest 6.18.0)25 Feb 2026
Broken access control
CVE-2025-15043
Medium 5.4Up to 6.15.13Fixed in a later version (latest 6.18.0)20 Jan 2026
Sensitive data exposure
CVE-2025-12192
Medium 5.3Up to 6.15.9Fixed in a later version (latest 6.18.0)5 Nov 2025
SQL injection
CVE-2025-12197
High 7.5Not yet publishedCheck for an update5 Nov 2025
Broken access control
CVE-2025-12175
Medium 4.3Up to 6.15.9Fixed in a later version (latest 6.18.0)31 Oct 2025
Sensitive data exposure
CVE-2025-9808
Medium 5.3Up to 6.15.2Fixed in a later version (latest 6.18.0)16 Sep 2025
SQL injection
CVE-2025-9807
High 7.5Up to 6.15.1Fixed in a later version (latest 6.18.0)12 Sep 2025
Cross-site scripting (XSS)
CVE-2025-5144
Medium 6.4Before 6.13.2.1Fixed in 6.13.2.111 Jun 2025
Cross-site scripting (XSS)
CVE-2024-8493
Medium 4.8Before 6.6.4Fixed in 6.6.415 May 2025
Cross-site scripting (XSS)
CVE-2024-12118
Medium 6.4Before 6.9.1Fixed in 6.9.123 Jan 2025
Security weakness
CVE-2024-5333
Medium 5.3Before 6.8.2.1Fixed in 6.8.2.116 Dec 2024
Cross-site scripting (XSS)
CVE-2024-6931
High 7.2Before 6.6.4Fixed in 6.6.427 Sep 2024
SQL injection
CVE-2024-8275
Critical 9.8Before 6.6.4.1Fixed in 6.6.4.125 Sep 2024
Security weakness
CVE-2024-1295
Medium 6.5Before 6.4.0.1Fixed in 6.4.0.114 Jun 2024
Cross-site scripting (XSS)
CVE-2024-4180
Critical 9.1Before 6.4.0.1Fixed in 6.4.0.14 Jun 2024
Sensitive data exposure
CVE-2023-6557
Medium 5.3Up to 6.2.8.2Fixed in a later version (latest 6.18.0)5 Feb 2024
Security weakness
CVE-2023-6203
High 7.5Before 6.2.8.1Fixed in 6.2.8.118 Dec 2023
Cross-site scripting (XSS)
CVE-2019-15109
Medium 6.1Before 4.8.2Fixed in 4.8.221 Aug 2019
Read the published descriptions
CVE-2026-95606, 7 Oct 2026
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection. This issue affects The Events Calendar: from n/a through 6.17.4. CVE record
CVE-2026-78006, 12 Sep 2026
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attribute before unserialize() is reached. This makes it possible for unauthenticated attackers to execute code on the server. This is exploitable without authentication or approval because the plugin's V2 single-event template runs do_blocks() over buffered comment HTML, and WordPress returns a moderation-hash URL that allows an unauthenticated commenter to immediately view their own pending comment, delivering the injected block markup to the vulnerable code path before any moderation occurs. This does require comments to be enabled and visible on events. CVE record
CVE-2026-78159, 12 Sep 2026
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the targeted site has comments enabled on tribe_events posts and that at least one comment containing a crafted wp:legacy-widget block has been submitted, as the attack chain is triggered when do_blocks() processes the single-event HTML including the comment area. CVE record
CVE-2026-3585, 10 Mar 2026
The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.17 via the 'ajax_create_import' function. This makes it possible for authenticated attackers, with Author-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. CVE record
CVE-2026-2694, 25 Feb 2026
The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to an improper capability check on the 'can_edit' and 'can_delete' function in all versions up to, and including, 6.15.16. This makes it possible for authenticated attackers, with Contributor-level access and above, to update or trash events, organizers and venues via REST API. CVE record
CVE-2025-15043, 20 Jan 2026
The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'start_migration', 'cancel_migration', and 'revert_migration' functions in all versions up to, and including, 6.15.13. This makes it possible for authenticated attackers, with subscriber level access and above, to start, cancel, or revert the Custom Tables V1 database migration, including dropping the custom database tables entirely via the revert action. CVE record
CVE-2025-12192, 5 Nov 2025
The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.9. The sysinfo REST endpoint compares the provided key to the stored opt-in key using a loose comparison, allowing unauthenticated attackers to send a boolean value and obtain the full system report whenever "Yes, automatically share my system information with The Events Calendar support team" setting is enabled. CVE record
CVE-2025-12197, 5 Nov 2025
The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15.1.1 to 6.15.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2025-12175, 31 Oct 2025
The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'tec_qr_code_modal' AJAX endpoint in all versions up to, and including, 6.15.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view draft event names and generate/view QR codes for them. CVE record
CVE-2025-9808, 16 Sep 2025
The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract information about password-protected vendors or venues. CVE record
CVE-2025-9807, 12 Sep 2025
The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all versions up to, and including, 6.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2025-5144, 11 Jun 2025
The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, 6.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-8493, 15 May 2025
The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
CVE-2024-12118, 23 Jan 2025
The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget through the html_tag attribute in all versions up to, and including, 6.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-5333, 16 Dec 2024
The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events. CVE record
CVE-2024-6931, 27 Sep 2024
The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-8275, 25 Sep 2024
The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Only sites that have manually added tribe_has_next_event() will be vulnerable to this SQL injection. CVE record
CVE-2024-1295, 14 Jun 2024
The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldn't have access to. (e.g. password-protected events, drafts, etc.) CVE record
CVE-2024-4180, 4 Jun 2024
The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX. CVE record
CVE-2023-6557, 5 Feb 2024
The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it possible for unauthenticated attackers to extract potentially sensitive data including post titles and IDs of pending, private and draft posts. CVE record
CVE-2023-6203, 18 Dec 2023
The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request CVE record
CVE-2019-15109, 21 Aug 2019
The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter. CVE record

What to do if you run The Events Calendar

If you run The Events Calendar, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new The Events Calendar vulnerabilities

Free. We email you when a new vulnerability is published for The Events Calendar, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support