CVE-2026-95606
- EPSS 0.33%
- Veröffentlicht 07.10.2026 17:07:23
- Zuletzt bearbeitet 08.10.2026 17:24:31
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection. This issue affects The Events Calendar: from n/a through 6.17.4.
CVE-2026-78159
- EPSS 0.76%
- Veröffentlicht 12.09.2026 07:39:15
- Zuletzt bearbeitet 14.09.2026 17:17:51
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array ...
CVE-2026-78006
- EPSS 0.78%
- Veröffentlicht 12.09.2026 07:39:15
- Zuletzt bearbeitet 14.09.2026 20:16:52
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be...
CVE-2026-49772
- EPSS 0.35%
- Veröffentlicht 16.06.2026 09:04:02
- Zuletzt bearbeitet 16.06.2026 14:52:36
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6.15.12 through 6.16.2.
CVE-2026-3585
- EPSS 0.35%
- Veröffentlicht 10.03.2026 03:33:51
- Zuletzt bearbeitet 22.04.2026 21:27:27
The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.17 via the 'ajax_create_import' function. This makes it possible for authenticated attackers, with Author-level access and above, ...
CVE-2026-2694
- EPSS 0.23%
- Veröffentlicht 25.02.2026 21:25:02
- Zuletzt bearbeitet 15.04.2026 00:35:42
The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to an improper capability check on the 'can_edit' and 'can_delete' function in all versions up to, and including, 6.15.16. This makes...
CVE-2025-15043
- EPSS 0.19%
- Veröffentlicht 20.01.2026 14:26:32
- Zuletzt bearbeitet 15.04.2026 00:35:42
The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'start_migration', 'cancel_migration', and 'revert_migration' functions in all versions up to, and including, 6.15.13. This mak...
CVE-2025-69352
- EPSS 0.18%
- Veröffentlicht 06.01.2026 16:36:40
- Zuletzt bearbeitet 07.10.2026 09:10:00
Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through <= 6.15.12.2.
CVE-2025-12192
- EPSS 0.26%
- Veröffentlicht 05.11.2025 09:27:40
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.9. The sysinfo REST endpoint compares the provided key to the stored opt-in key using a loose comparison, allowing unauthenticated...
CVE-2025-12197
- EPSS 17.09%
- Veröffentlicht 05.11.2025 04:36:58
- Zuletzt bearbeitet 15.04.2026 00:35:42
The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15.1.1 to 6.15.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL ...