CVE-2024-8493
- EPSS 0.24%
- Veröffentlicht 15.05.2025 20:15:58
- Zuletzt bearbeitet 04.06.2025 20:08:55
The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disal...
CVE-2024-5333
- EPSS 8.39%
- Veröffentlicht 16.12.2024 06:15:08
- Zuletzt bearbeitet 14.05.2025 20:16:11
The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.
CVE-2024-6931
- EPSS 35.46%
- Veröffentlicht 27.09.2024 09:15:04
- Zuletzt bearbeitet 04.10.2024 19:08:35
The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthent...
CVE-2024-8275
- EPSS 83.54%
- Veröffentlicht 25.09.2024 05:15:11
- Zuletzt bearbeitet 02.10.2024 19:14:54
The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and l...
CVE-2024-4180
- EPSS 42.37%
- Veröffentlicht 04.06.2024 06:15:10
- Zuletzt bearbeitet 29.05.2025 20:21:42
The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.
CVE-2023-6557
- EPSS 0.69%
- Veröffentlicht 05.02.2024 22:15:55
- Zuletzt bearbeitet 08.04.2026 19:18:56
The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it possible for unauthenticated at...
CVE-2023-6203
- EPSS 0.58%
- Veröffentlicht 18.12.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 08:43:21
The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request
CVE-2019-15109
- EPSS 0.15%
- Veröffentlicht 21.08.2019 12:15:11
- Zuletzt bearbeitet 21.11.2024 04:28:04
The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.