Home/Product/stellarwp the events calendar
Product

stellarwp the events calendar

16 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-5144
< 6.13.2.1
The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in
6.4MEDIUM
CVE-2024-8493
< 6.6.4
The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privil
4.8MEDIUM
CVE-2025-1402
< 5.19.1.2
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability che
5.3MEDIUM
CVE-2024-12118
< 6.9.1
The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget throu
6.4MEDIUM
CVE-2024-5333
< 6.8.2.1
The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users t
5.3MEDIUM
CVE-2024-6931
< 6.6.4
The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up t
7.2HIGH
CVE-2024-8275
< 6.6.4.1
The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event
9.8CRITICAL
CVE-2024-8016
< 7.0.2.1
The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.0.2 via
9.1CRITICAL
CVE-2024-1295
< 6.4.0.1
The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent user
6.5MEDIUM
CVE-2024-4180
< 6.4.0.1
The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views vi
9.1CRITICAL
CVE-2023-6557
<= 6.2.8.2
The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,
5.3MEDIUM
CVE-2023-6203
< 6.2.8.1
The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via
7.5HIGH
CVE-2021-25025
< 1.1.51
The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX
4.3MEDIUM
CVE-2021-25024
< 1.1.51
The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading
6.1MEDIUM
CVE-2019-15109
< 4.8.2
The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.
6.1MEDIUM
CVE-2015-5485
<= 3.10.1
Cross-site scripting (XSS) vulnerability in the Event Import page (import-eventbrite-events.php) in the Modern Tribe Eventbrite Ti
threatengine.sh