CVE-2026-3585
- EPSS 0.08%
- Veröffentlicht 10.03.2026 03:33:51
- Zuletzt bearbeitet 08.04.2026 18:26:04
The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.17 via the 'ajax_create_import' function. This makes it possible for authenticated attackers, with Author-level access and above, ...
CVE-2026-2694
- EPSS 0.06%
- Veröffentlicht 25.02.2026 21:25:02
- Zuletzt bearbeitet 15.04.2026 00:35:42
The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to an improper capability check on the 'can_edit' and 'can_delete' function in all versions up to, and including, 6.15.16. This makes...
CVE-2025-15043
- EPSS 0.06%
- Veröffentlicht 20.01.2026 14:26:32
- Zuletzt bearbeitet 15.04.2026 00:35:42
The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'start_migration', 'cancel_migration', and 'revert_migration' functions in all versions up to, and including, 6.15.13. This mak...
CVE-2025-69352
- EPSS 0.04%
- Veröffentlicht 06.01.2026 16:36:40
- Zuletzt bearbeitet 15.04.2026 00:35:42
Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through <= 6.15.12.2.
CVE-2025-12192
- EPSS 0.06%
- Veröffentlicht 05.11.2025 09:27:40
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.9. The sysinfo REST endpoint compares the provided key to the stored opt-in key using a loose comparison, allowing unauthenticated...
CVE-2025-12197
- EPSS 0.33%
- Veröffentlicht 05.11.2025 04:36:58
- Zuletzt bearbeitet 15.04.2026 00:35:42
The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15.1.1 to 6.15.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL ...
CVE-2025-12175
- EPSS 0.03%
- Veröffentlicht 31.10.2025 08:25:54
- Zuletzt bearbeitet 15.04.2026 00:35:42
The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'tec_qr_code_modal' AJAX endpoint in all versions up to, and including, 6.15.9. This makes it possible for authenticated attack...
CVE-2025-9808
- EPSS 1.15%
- Veröffentlicht 16.09.2025 05:25:26
- Zuletzt bearbeitet 15.04.2026 00:35:42
The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract information about password-protecte...
CVE-2025-9807
- EPSS 0.11%
- Veröffentlicht 12.09.2025 01:46:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all versions up to, and including, 6.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation o...
CVE-2025-5144
- EPSS 0.2%
- Veröffentlicht 11.06.2025 12:22:52
- Zuletzt bearbeitet 10.07.2025 00:25:36
The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, 6.13.2 due to insufficient input sanitization and output escaping. This makes it possible...