Stellarwp

The Events Calendar

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.24%
  • Veröffentlicht 15.05.2025 20:15:58
  • Zuletzt bearbeitet 04.06.2025 20:08:55

The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disal...

Exploit
  • EPSS 8.39%
  • Veröffentlicht 16.12.2024 06:15:08
  • Zuletzt bearbeitet 14.05.2025 20:16:11

The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.

  • EPSS 35.46%
  • Veröffentlicht 27.09.2024 09:15:04
  • Zuletzt bearbeitet 04.10.2024 19:08:35

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthent...

  • EPSS 83.54%
  • Veröffentlicht 25.09.2024 05:15:11
  • Zuletzt bearbeitet 02.10.2024 19:14:54

The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and l...

Exploit
  • EPSS 42.37%
  • Veröffentlicht 04.06.2024 06:15:10
  • Zuletzt bearbeitet 29.05.2025 20:21:42

The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.

  • EPSS 0.69%
  • Veröffentlicht 05.02.2024 22:15:55
  • Zuletzt bearbeitet 08.04.2026 19:18:56

The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it possible for unauthenticated at...

Exploit
  • EPSS 0.58%
  • Veröffentlicht 18.12.2023 20:15:08
  • Zuletzt bearbeitet 21.11.2024 08:43:21

The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request

  • EPSS 0.15%
  • Veröffentlicht 21.08.2019 12:15:11
  • Zuletzt bearbeitet 21.11.2024 04:28:04

The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.