Product
stellarwp the events calendar
16 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-5144
CVE-2024-8493
CVE-2025-1402
CVE-2024-12118
CVE-2024-5333
CVE-2024-6931
CVE-2024-8275
CVE-2024-8016
CVE-2024-1295
CVE-2024-4180
CVE-2023-6557
CVE-2023-6203
CVE-2021-25025
CVE-2021-25024
CVE-2019-15109
CVE-2015-5485
< 6.13.2.1
The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in
< 6.6.4
The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privil
< 5.19.1.2
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability che
< 6.9.1
The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget throu
< 6.8.2.1
The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users t
< 6.6.4
The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up t
< 6.6.4.1
The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event
< 7.0.2.1
The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.0.2 via
< 6.4.0.1
The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent user
< 6.4.0.1
The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views vi
<= 6.2.8.2
The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,
< 6.2.8.1
The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via
< 1.1.51
The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX
< 1.1.51
The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading
< 4.8.2
The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.
<= 3.10.1
Cross-site scripting (XSS) vulnerability in the Event Import page (import-eventbrite-events.php) in the Modern Tribe Eventbrite Ti