{"error":0,"message":null,"data":{"name":"The Events Calendar","plugin":"the-events-calendar","link":"https:\/\/wordpress.org\/plugins\/the-events-calendar\/","latest":"1789685820","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"a757791e30e6e913e3a582d268551ed966e9568f3c0e784efe2c8b6ef88ab79a","name":"The Events Calendar [the-events-calendar] < 4.8.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.8.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-15109","name":"CVE-2019-15109","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-15109","description":"[en] The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.","date":"2019-08-21"},{"id":"1f382ee56e570aa5ca31f46193ee07819b9532b1","name":"The Events Calendar <= 4.8.1 - Cross-Site Scripting via tribe_paged Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-481-cross-site-scripting-via-tribe-paged-parameter","description":"The Events Calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.","date":"2019-03-04"},{"id":"b595e8b3-4cf3-4f90-9ce6-315648711de4","name":"The Events Calendar &lt; 4.8.2 - XSS","link":"https:\/\/wpscan.com\/vulnerability\/b595e8b3-4cf3-4f90-9ce6-315648711de4","description":"The The Events Calendar WordPress plugin was affected by a XSS security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"220141ebb447edff4307de6804aab85e576cefc6dce9882f261c7720921c2076","name":"The Events Calendar [the-events-calendar] < 5.14.0.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.14.0.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a61233d4c512052f4ec67d4ea39c1bb30a4091ac","name":"WordPress The Events Calendar plugin < 5.14.0.4 - Sensitive Information Disclosure vulnerability","link":"https:\/\/patchstack.com\/database\/vulnerability\/the-events-calendar-\/wordpress-the-events-calendar-plugin-51404-sensitive-information-disclosure-vulnerability","description":"Sensitive Information Disclosure vulnerability discovered in WordPress The Events Calendar plugin (versions < 5.14.0.4).","date":"2022-02-28"}],"impact":[]},{"uuid":"e0a2cdb8fd031287338bc371ae6f384323e593f10f0789864367709264b280fe","name":"The Events Calendar [the-events-calendar] < 5.14.0.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.14.0.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2c9e62f0747b35661e5a3b5c5676939983b8c1de","name":"WordPress The Events Calendar plugin < 5.14.0.4 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/vulnerability\/the-events-calendar-\/wordpress-the-events-calendar-plugin-51404-toggle-the-debug-mode-via-cross-site-request-forgery-csrf-vulnerability","description":"Sensitive Information Disclosure vulnerability discovered in WordPress The Events Calendar plugin (versions < 5.14.0.4).","date":"2022-02-28"}],"impact":[]},{"uuid":"5e282a598df3fffe36a97ecef86078111e382341ad022fe34526c20c3238624f","name":"The Events Calendar [the-events-calendar] < 4.1.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a0bc6292a861b8ea327629208d78b4715e64de2e","name":"WordPress The Events Calendar Plugin <= 4.1.1 - Open Redirection","link":"https:\/\/patchstack.com\/database\/vulnerability\/the-events-calendar-\/wordpress-the-events-calendar-plugin-4-1-1-open-redirection","description":"This plugin is prone to an open redirection vulnerability in the \"tribe-bar-view\" parameter.\nUpdate the plugin.","date":"2016-04-25"}],"impact":[]},{"uuid":"1ce09217c2190983e61b2ec707eac62eeb65643aad5d2c3ec78f7252f9748348","name":"The Events Calendar [the-events-calendar] < 3.0.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e952ff0d125fc56920848e49905ef66616e150e1","name":"WordPress The Events Calendar Plugin <= 3.0 - Reflected Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/vulnerability\/the-events-calendar-\/wordpress-the-events-calendar-plugin-3-0-reflected-cross-site-scripting","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate the plugin.","date":"2014-08-01"}],"impact":[]},{"uuid":"55e91672757e7ece6890aef4781e8e8560e4510d9d063a111df9b40f1cf5cca8","name":"The Events Calendar [the-events-calendar] < 5.14.0.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.14.0.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6dae6dca-7474-4008-9fe5-4c62b9f12d0a","name":"Unauthorised AJAX Calls via Freemius","link":"https:\/\/wpscan.com\/vulnerability\/6dae6dca-7474-4008-9fe5-4c62b9f12d0a","description":"The plugins and themes use an insecure version of the Freemius Framework, which is lacking CSRF and\/or authorisation in some of its AJAX actions. As a result, any authenticated users, such as subscriber could access the debug logs. Unauthenticated attackers could also make a logged in admin toggle the debug mode via a CSRF attack.","date":null}],"impact":[]},{"uuid":"4d3c27527d54dbce99acdee17f42e8b00a970428c8fb97b9da14b704cb7e5fe6","name":"The Events Calendar [the-events-calendar] < 5.14.0.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.14.0.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6d8910c719b2a132ec93828cd37e418b19cac960","name":"Freemius SDK <= 2.4.2 - Missing Authorization Checks","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/freemius-sdk-242-missing-authorization-checks","description":"The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.","date":"2022-03-04"},{"id":"CVE-2022-4974","name":"Freemius SDK <= 2.4.2 - Missing Authorization Checks","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-4974","description":"The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.","date":"2024-10-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"l","a":"l","score":"6.3","severity":"m","exploitable":"2.8","impact":"3.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:L","score":"6.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"3.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8225935698a56badd0127ee1398669ebe84a687774399b33583db530364114dd","name":"The Events Calendar [the-events-calendar] < 4.1.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3b974251c4a571efab932fdc05a0c1f920c8c6d5","name":"The Events Calendar < 4.1.1.1 - Open Redirect","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-4111-open-redirect","description":"The Events Calendar plugin for WordPress is vulnerable to an open redirect vulnerability in versions before 4.1.1.1. This allows attackers to redirect victims to an untrusted site via a crafted link on a vulnerable trusted site.","date":"2016-04-25"}],"impact":[]},{"uuid":"fe191ec65868c4c96292022c66e04c7b13842c0d57ca52cdc526e25901570643","name":"The Events Calendar [the-events-calendar] < 6.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-35777","name":"CVE-2023-35777","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-35777","description":"[en] Missing Authorization vulnerability in The Events Calendar The Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n\/a through 6.1.2.2.","date":"2024-12-13"},{"id":"cfce723013aabd6faa6bb7ce22fb883007939bf7","name":"The Events Calendar <= 6.1.2.2 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-6122-missing-authorization","description":"The The Events Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_ical_output_for_an_event() function in versions up to, and including, 6.1.2.2. This makes it possible for unauthenticated attackers to view arbitrary\/private event content.","date":"2023-07-25"},{"id":"ca047e65921a35ee6c28527766bc1a91c04ec15c","name":"WordPress  The Events Calendar Plugin  <= 6.1.2.2 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/the-events-calendar\/vulnerability\/wordpress-the-events-calendar-plugin-6-1-2-2-broken-access-control-vulnerability","description":"Update the WordPress The Events Calendar plugin to the latest available version (at least 6.1.3).\nPetiteMais discovered and reported this Broken Access Control vulnerability in WordPress The Events Calendar Plugin.  This vulnerability has been fixed in version 6.1.3.","date":"2023-07-25"},{"id":"EUVD-2023-39776","name":"EUVD-2023-39776","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2023-39776","description":"Missing Authorization vulnerability in The Events Calendar The Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n\/a through 6.1.2.2.","date":"2024-12-13"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.002"}},{"uuid":"575ac6064a4141a9b81697242ab2ec4217fafe87e29c7db32c7fea08d705b14b","name":"The Events Calendar [the-events-calendar] < 6.1.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.1.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-33999","name":"CVE-2023-33999","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-33999","description":"[en] Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS.\n\nThis issue affects WP Mail Log: from n\/a through 1.0.2.","date":"2026-06-11"},{"id":"81b9eb6eb947bd71d8dcbb2592d0fcb27f8ae5b2","name":"WordPress  The Events Calendar Plugin  <= 6.0.13.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/the-events-calendar\/vulnerability\/wordpress-the-events-calendar-plugin-6-0-13-1-reflected-cross-site-scripting-xss-vulnerability","description":"Update the WordPress The Events Calendar plugin to the latest available version.\nRafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress The Events Calendar Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 6.1.0.","date":"2023-07-19"},{"id":"35d2f1e7-a4f8-49fd-a8dd-bb2c26710f93","name":"Freemius SDK &lt; 2.5.10 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/35d2f1e7-a4f8-49fd-a8dd-bb2c26710f93","description":"The Freemius SDK for WordPress does not adequately sanitize inputs or escape outputs, leading to Reflected Cross-Site Scripting. This directly affects over 1000 plugins and themes that use this SDK.","date":"2023-07-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8931a958f4b9c30369385cf34bf3f290a4780d705fed74d2ebf85342f76f82f4","name":"The Events Calendar [the-events-calendar] < 3.0.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"435ca477c702984e66ef2ae934c9f346535a5cf7","name":"WordPress  The Events Calendar Plugin  <= 3.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/the-events-calendar\/vulnerability\/wordpress-the-events-calendar-plugin-3-0-reflected-cross-site-scripting","description":"Update the plugin.\nAn unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress The Events Calendar Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.0.1.","date":"2023-08-01"}],"impact":[]},{"uuid":"2ef44d230bbc4fa06a6b40408c815655222f5119b36b1be51025f8ca3020c3b6","name":"The Events Calendar [the-events-calendar] < 4.1.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"05dcb3501757a6e40b61e256ab88a44c8f6576df","name":"WordPress  The Events Calendar Plugin  <= 4.1.1 is vulnerable to Open Redirection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/the-events-calendar\/vulnerability\/wordpress-the-events-calendar-plugin-4-1-1-open-redirection","description":"Update the plugin.\nPaul Mynarsky discovered and reported this Open Redirection vulnerability in WordPress The Events Calendar Plugin. This could allow a malicious actor to redirect users from one site to the other due to the redirect URL not being validated. Users could be tricked to visiting a legitimate site to then be redirected to a malicious site and cause a phishing incident. This vulnerability has been fixed in version 4.1.1.1.","date":"2023-04-25"}],"impact":[]},{"uuid":"6a7f79edc7f7b5f0e16ceefd6aac6992be75ecf1526d671964f832a014bafdd2","name":"The Events Calendar [the-events-calendar] < 5.14.0.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.14.0.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"83bc58b6c2554ddddd6a3e5778ff934cf47bf128","name":"WordPress  The Events Calendar Plugin  < 5.14.0.4 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/the-events-calendar\/vulnerability\/wordpress-the-events-calendar-plugin-51404-toggle-the-debug-mode-via-cross-site-request-forgery-csrf-vulnerability","description":"Update the WordPress The Events Calendar plugin to the latest available version (at least 5.14.0.4).\nAn unknown person discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress The Events Calendar Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 5.14.0.4.","date":"2023-02-28"}],"impact":[]},{"uuid":"65e246a7ec50c34ae925fe1307b110d29437657a5740d4e3fda43f1aec302b90","name":"The Events Calendar [the-events-calendar] < 5.14.0.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.14.0.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"fddc71c551ebe927af92f1987a72062b38c04610","name":"WordPress  The Events Calendar Plugin  < 5.14.0.4 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/the-events-calendar\/vulnerability\/wordpress-the-events-calendar-plugin-51404-sensitive-information-disclosure-vulnerability","description":"Update the WordPress The Events Calendar plugin to the latest available version (at least 5.14.0.4).\nAn unknown person discovered and reported this Sensitive Data Exposure vulnerability in WordPress The Events Calendar Plugin.  This vulnerability has been fixed in version 5.14.0.4.","date":"2023-02-28"}],"impact":[]},{"uuid":"d7899bb974a69e4ca2119b977a3d579d07c839949dd59644b049c9d5b18dc383","name":"The Events Calendar [the-events-calendar] < 4.1.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"59acb0f7-9150-44bd-ba1f-cd944b56ff41","name":"The Events Calendar &lt;= 4.1.1 - Open Redirect","link":"https:\/\/wpscan.com\/vulnerability\/59acb0f7-9150-44bd-ba1f-cd944b56ff41","description":"The problem is located in the &quot;tribe-bar-view&quot; parameter that can be used to \r\nredirect a user to an arbitrary website.\r\n\r\nTimeline\r\n* 2016-04-04 : Initial contact with Modern Tribe\r\n* 2016-04-05 : Modern Tribe confirms the report\r\n* 2016-04-07 : Modern Tribe publishes a new version (4.1.1.1) that resolves the issue","date":null}],"impact":[]},{"uuid":"640106d20f70a9b709431a6e70b52465d7b6a5a78a44a730855a7b9e9494f497","name":"The Events Calendar [the-events-calendar] < 3.0.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"57c478a8-9a2d-4f0b-9f9a-9f78b92abf69","name":"The Events Calendar &lt;= 3.0 - Reflected Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/57c478a8-9a2d-4f0b-9f9a-9f78b92abf69","description":"The The Events Calendar WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"a24653544ba2adcdefce719bd3dad80bc1423ba02f6484f3dbe352d472dcfb8c","name":"The Events Calendar [the-events-calendar] < 5.14.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.14.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"533f213b-9fb7-47da-a42c-780aea3aee11","name":"The Events Calendar &lt; 5.14.0 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/533f213b-9fb7-47da-a42c-780aea3aee11","description":"The plugin does not escape an aggregator URL before outputting it back in an attribute, leading to Reflected Cross-Site Scripting","date":null}],"impact":[]},{"uuid":"d38474301b0861f60dd9d0baa2e4cdf6e7ae2296ae2328cadf9a67effafc9995","name":"The Events Calendar [the-events-calendar] < 6.2.8.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.2.8.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"392171a3fe3230ecf0fc8e8d795071740c32dffe","name":"The Events Calendar <= 6.2.8 - Information Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-628-information-disclosure","description":"The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.2.8 via the get_data function. This makes it possible for unauthenticated attackers to extract sensitive data including private post content, via the REST API.","date":"2023-11-20"},{"id":"CVE-2023-6203","name":"CVE-2023-6203","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6203","description":"[en] The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request","date":"2023-12-18"},{"id":"229273e6-e849-447f-a95a-0730969ecdae","name":"The Events Calendar &lt; 6.2.8.1 - Unauthenticated Arbitrary Password Protected Post Read","link":"https:\/\/wpscan.com\/vulnerability\/229273e6-e849-447f-a95a-0730969ecdae","description":"The plugin discloses the content of password protected posts to unauthenticated users via a crafted request","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-287","name":"Improper Authentication","description":"When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct."}]}},{"uuid":"1e03ad4c3b3a50e5e451a66bd9aa7868f4aaf6d70afd568d5547e97bf5e8d7f3","name":"The Events Calendar [the-events-calendar] < 6.2.8.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.2.8.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"cb4ccc2c1070be47b4b666568c12ef9bfb6e07d6","name":"WordPress  The Events Calendar Plugin  < 6.2.8.1 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/the-events-calendar\/vulnerability\/wordpress-the-events-calendar-plugin-6-2-8-information-disclosure-vulnerability","description":"Update the WordPress Event Single Page Templates Addon For The Events Calendar plugin to the latest available version (at least 6.2.8.1).\nUnknown discovered and reported this Sensitive Data Exposure vulnerability in WordPress The Events Calendar Plugin.  This vulnerability has been fixed in version 6.2.8.1.","date":"2023-11-22"}],"impact":[]},{"uuid":"75cd2871bb956a842cef568a37648c066216cb1779adcd6fc4cedf6820e4741a","name":"The Events Calendar [the-events-calendar] < 6.2.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.2.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6557","name":"CVE-2023-6557","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6557","description":"[en] The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it possible for unauthenticated attackers to extract potentially sensitive data including post titles and IDs of pending, private and draft posts.","date":"2024-02-05"},{"id":"b51777b776a19b0d64bd23096fe7b4e87b2e2d94","name":"The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-6282-unauthenticated-sensitive-information-exposure","description":"The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it possible for unauthenticated attackers to extract potentially sensitive data including post titles and IDs of pending, private and draft posts.","date":"2024-01-12"},{"id":"f2b40fde09bf095f27cd004dd61ff4b2285832d5","name":"WordPress  The Events Calendar Plugin  <= 6.2.8.2 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/the-events-calendar\/vulnerability\/wordpress-the-events-calendar-plugin-6-2-8-2-unauthenticated-sensitive-information-exposure-vulnerability","description":"Update the WordPress The Events Calendar plugin to the latest available version (at least 6.2.9).\nNicolas Decayeux discovered and reported this Sensitive Data Exposure vulnerability in WordPress The Events Calendar Plugin.  This vulnerability has been fixed in version 6.2.9.\nHave additional information or questions about this entry? Get in touch.","date":"2024-01-15"},{"id":"27b3156e-25af-4976-876e-db364a366213","name":"The Events Calendar &lt; 6.2.9 - Unauthenticated Sensitive Information Exposure","link":"https:\/\/wpscan.com\/vulnerability\/27b3156e-25af-4976-876e-db364a366213","description":"The plugin is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it possible for unauthenticated attackers to extract potentially sensitive data including post titles and IDs of pending, private and draft posts.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"65c61b2a0a4c5de3a9fec60c313eae425520defe0f3f98b118cabe070f6d6b76","name":"The Events Calendar [the-events-calendar] < 6.3.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.3.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-31433","name":"CVE-2024-31433","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-31433","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in StellarWP The Events Calendar the-events-calendar.This issue affects The Events Calendar: from n\/a through <= 6.3.0.","date":"2024-04-15"},{"id":"5eb461eab2f487431d207d780c841dd03c6e3509","name":"WordPress  The Events Calendar Plugin    <= 6.3.0 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/the-events-calendar\/vulnerability\/wordpress-the-events-calendar-plugin-6-3-0-cross-site-request-forgery-csrf-vulnerability","description":"Update the WordPress The Events Calendar plugin to the latest available version (at least 6.3.1).\nDhabaleshwar Das discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress The Events Calendar Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 6.3.1.\nThis vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"0a6fe65169f4fcb5d5c8a400930c8ca82c0da7a6","name":"The Events Calendar <= 6.3.0 - Cross-Site Request Forgery to Notice Dismissal","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-630-cross-site-request-forgery-to-notice-dismissal","description":"The The Events Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.3.0. This is due to missing or incorrect nonce validation on the maybe_dismiss() function. This makes it possible for unauthenticated attackers to dismiss notices via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-04-10"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"78e0ae34268b25b2fc9993a6f8126389ba549637dd566880416364767553f3cc","name":"The Events Calendar [the-events-calendar] < 6.4.0.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.4.0.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4180","name":"CVE-2024-4180","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4180","description":"[en] The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.","date":"2024-06-04"},{"id":"fc3ecd807bd54da2b7621dfde90f1e4ebfdedb4c","name":"WordPress The Events Calendar Plugin < 6.4.0.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/the-events-calendar\/vulnerability\/wordpress-the-events-calendar-plugin-6-4-0-1-reflected-xss-vulnerability","description":"<p>WordPress The Events Calendar Plugin < 6.4.0.1 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: The Events Calendar<\/p><p>Link: https:\/\/wordpress.org\/plugins\/the-events-calendar\/#developers<\/p><p>Affected Version < 6.4.0.1<\/p><p>Fixed in version 6.4.0.1 <\/p>","date":"2024-05-15"},{"id":"675005560fc54997f072cb1a31c291693f62dab4","name":"The Events Calendar <= 6.4.0 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-640-reflected-cross-site-scripting","description":"The The Events Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view_data' parameter in all versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2024-05-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"n","score":"9.1","severity":"c","exploitable":"3.9","impact":"5.2"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:N","score":"9.1","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"none","exploitable":"3.9","impact":"5.2"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"38621d608400536371cee412a40da727307e79eb7134e29bdca1b94392f436be","name":"The Events Calendar [the-events-calendar] < 6.4.0.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.4.0.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1295","name":"CVE-2024-1295","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1295","description":"[en] The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldn't have access to. (e.g. password-protected events, drafts, etc.)","date":"2024-06-14"},{"id":"c462b4956c54df8905dad89f410f5a07dbecc156","name":"The Events Calendar Free & Pro <= 6.4.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Events Access","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/the-events-calendar-free-pro-640-missing-authorization-to-authenticated-contributor-arbitrary-events-access","description":"Multiple plugins and\/or themes for WordPress are vulnerable to unauthorized access of data due to a insufficient capability checks and restrictions on a function in various versions. This makes it possible for authenticated attackers, with Contributor-level access and above, to access arbitrary events that they should not have access to.","date":"2024-05-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-284","name":"Improper Access Control","description":"The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"db87db239e7d6dc6397b67e5d5fcd6f5d4cb12ffe1235b9d1550da381a8c58ae","name":"The Events Calendar [the-events-calendar] < 6.5.1.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.5.1.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-37518","name":"CVE-2024-37518","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-37518","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in StellarWP The Events Calendar the-events-calendar allows Cross Site Request Forgery.This issue affects The Events Calendar: from n\/a through <= 6.5.1.4.","date":"2025-01-02"},{"id":"2d6f5722933121d477da754f0312c94fafb95b57","name":"WordPress The Events Calendar Plugin <= 6.5.1.4 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/the-events-calendar\/vulnerability\/wordpress-the-events-calendar-plugin-6-5-1-4-cross-site-request-forgery-csrf-vulnerability","description":"<p>WordPress The Events Calendar Plugin <= 6.5.1.4 is vulnerable to Cross Site Request Forgery (CSRF)<\/p><p>Software: The Events Calendar<\/p><p>Link: https:\/\/wordpress.org\/plugins\/the-events-calendar\/#developers<\/p><p>Affected Version <= 6.5.1.4<\/p><p>Fixed in version 6.5.1.5 <\/p>","date":"2024-07-05"},{"id":"be2c11454fc253ad421bd7db9773d74d575acda6","name":"The Events Calendar <= 6.5.1.4 - Cross-Site Request Forgery via action_restore_events","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-6514-cross-site-request-forgery-via-action-restore-events","description":"The The Events Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.5.1.4. This is due to missing or incorrect nonce validation on the action_restore_events() function. This makes it possible for unauthenticated attackers to restore events via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-07-05"},{"id":"EUVD-2024-36581","name":"EUVD-2024-36581","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-36581","description":"Cross-Site Request Forgery (CSRF) vulnerability in The Events Calendar The Events Calendar allows Cross Site Request Forgery.This issue affects The Events Calendar: from n\/a through 6.5.1.4.","date":"2025-01-02"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"b512b45e8e8654e2e0ade9287a4994333b0dfd8b9ef2725a60f31294028b099d","name":"The Events Calendar [the-events-calendar] < 6.6.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.6.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-6931","name":"CVE-2024-6931","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-6931","description":"[en] The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-09-27"},{"id":"d03023cad487630b5658b9fc634124b90e950e15","name":"WordPress The Events Calendar Plugin <= 6.5.1.6 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/vulnerability\/the-events-calendar\/wordpress-the-events-calendar-plugin-6-5-1-6-unauthenticated-stored-cross-site-scripting-vulnerability","description":"<p>WordPress The Events Calendar Plugin <= 6.5.1.6 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: The Events Calendar<\/p><p>Link: https:\/\/wordpress.org\/plugins\/the-events-calendar\/#developers<\/p><p>Affected Version <= 6.5.1.6<\/p><p>Fixed in version 6.5.2 <\/p>","date":"2024-07-24"},{"id":"fa902b3f34718bf43acbef290f005d92b53f55d5","name":"The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-652-unauthenticated-stored-cross-site-scripting","description":"The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-07-23"},{"id":"ceac669108c7789845ab13f2e9704581615025ab","name":"WordPress The Events Calendar Plugin <= 6.6.3 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/the-events-calendar\/vulnerability\/wordpress-the-events-calendar-plugin-6-6-3-unauthenticated-stored-cross-site-scripting-vulnerability","description":"<p>WordPress The Events Calendar Plugin <= 6.6.3 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: The Events Calendar<\/p><p>Link: https:\/\/wordpress.org\/plugins\/the-events-calendar\/#developers<\/p><p>Affected Version <= 6.6.3<\/p><p>Fixed in version 6.6.4 <\/p>","date":"2024-09-27"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"747bb3a72ece7d3d44bd2fe687880f35dd58bbf96ae7ea4627973c8770f2d2ef","name":"The Events Calendar [the-events-calendar] < 6.6.4.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.6.4.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-8275","name":"CVE-2024-8275","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-8275","description":"[en] The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Only sites that have manually added tribe_has_next_event() will be vulnerable to this SQL injection.","date":"2024-09-25"},{"id":"8cb146b9d121a4413d221eb3f49f697f9100b2b6","name":"WordPress The Events Calendar Plugin <= 6.6.4 is vulnerable to SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/the-events-calendar\/vulnerability\/wordpress-the-events-calendar-plugin-6-6-4-unauthenticated-sql-injection-vulnerability","description":"<p>WordPress The Events Calendar Plugin <= 6.6.4 is vulnerable to SQL Injection<\/p><p>Software: The Events Calendar<\/p><p>Link: https:\/\/wordpress.org\/plugins\/the-events-calendar\/#developers<\/p><p>Affected Version <= 6.6.4<\/p><p>Fixed in version 6.6.4.1 <\/p>","date":"2024-09-25"},{"id":"77e645b06d84e736a29d3ef4bab06955dd80fb37","name":"The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-664-unauthenticated-sql-injection","description":"The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Only sites that have manually added tribe_has_next_event() will be vulnerable to this SQL injection.","date":"2024-09-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"d723f123178f1b5f155aa402e5039e095d6fbc1270cd0bb369cdad21b0ab57c2","name":"The Events Calendar [the-events-calendar] < 6.6.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.6.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-8493","name":"The Events Calendar < 6.6.4 - Admin+ Stored XSS","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-8493","description":"The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","date":"0000-00-00"},{"id":"ee4f00ee8b15a5a79c90903383f4c5b2504d09a6","name":"The Events Calendar <= 6.6.3 - Authenticated (Administrator+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-663-authenticated-administrator-stored-cross-site-scripting","description":"The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-07-31"},{"id":"EUVD-2025-15219","name":"EUVD-2025-15219","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-15219","description":"The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","date":"2025-05-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"359bc9f81e0b10ec668395223cbf88d292da81ae3243607eb417127cc46e54c2","name":"The Events Calendar [the-events-calendar] < 6.8.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.8.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-5333","name":"CVE-2024-5333","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-5333","description":"[en] The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.","date":"2024-12-16"},{"id":"2f140f6c4898f0ce4d76b079956ec9807af24e16","name":"WordPress The Events Calendar Plugin < 6.8.2.1 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/the-events-calendar\/vulnerability\/wordpress-the-events-calendar-plugin-6-8-2-1-unauthenticated-password-protected-event-disclosure-vulnerability","description":"<p>WordPress The Events Calendar Plugin < 6.8.2.1 is vulnerable to Broken Access Control<\/p><p>Software: The Events Calendar<\/p><p>Fixed in version 6.8.2.1 <\/p><p>Affected Version < 6.8.2.1<\/p><p>CVE: CVE-2024-5333<\/p>","date":"2024-12-16"},{"id":"63ff8eeb024979ed2cb77a2484f6fa7d88224eb9","name":"The Events Calendar <= 6.8.2 - Missing Authorization to Unauthenticated Password Protected Event Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-682-missing-authorization-to-unauthenticated-password-protected-event-disclosure","description":"The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.8.2 via the \/wp-json\/tribe\/events\/v1\/events\/ REST API due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected events that they should not have access to.","date":"2024-11-25"},{"id":"EUVD-2024-47146","name":"EUVD-2024-47146","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-47146","description":"The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.","date":"2024-12-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"d39f96f321593ba8ab41d1cefdaee2bb4a39bc2e1deeddc12c8fc45b7ef89ee4","name":"The Events Calendar [the-events-calendar] < 6.9.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.9.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-12118","name":"CVE-2024-12118","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-12118","description":"[en] The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget through the html_tag attribute in all versions up to, and including, 6.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-01-23"},{"id":"767b1ebc3f7bbdfedbf18c57b91fee294d17c11e","name":"The Events Calendar <= 6.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-690-authenticated-contributor-stored-cross-site-scripting","description":"The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget through the html_tag attribute in all versions up to, and including, 6.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-01-22"},{"id":"EUVD-2024-50610","name":"EUVD-2024-50610","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-50610","description":"The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget through the html_tag attribute in all versions up to, and including, 6.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-01-23"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"996d5bf3dcaf6f4b5ef6474d6192cf3e78db212c0cc6da85c0956dde4bc9c972","name":"The Events Calendar [the-events-calendar] < 6.7.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.7.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-24537","name":"CVE-2025-24537","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-24537","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in StellarWP The Events Calendar the-events-calendar allows Cross Site Request Forgery.This issue affects The Events Calendar: from n\/a through <= 6.7.0.","date":"2025-01-27"},{"id":"EUVD-2025-3749","name":"EUVD-2025-3749","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-3749","description":"Cross-Site Request Forgery (CSRF) vulnerability in The Events Calendar The Events Calendar allows Cross Site Request Forgery. This issue affects The Events Calendar: from n\/a through 6.7.0.","date":"2025-01-27"},{"id":"2267a1d9494c64af1cf31208480769357fe09a88","name":"The Events Calendar <= 6.7.0 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-670-cross-site-request-forgery","description":"The The Events Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.7.0. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site administrator into performing an action such as clicking on a link. The impact of this vulnerability is unknown.","date":"2025-01-09"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4709d34d3a08b4a12a720c912fecd69ae0d9d49b313e9540ce5355b0c3ac4776","name":"The Events Calendar [the-events-calendar] < 6.12.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.12.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-48246","name":"CVE-2025-48246","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-48246","description":"[en] Missing Authorization vulnerability in The Events Calendar The Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Events Calendar: from n\/a through 6.11.2.1.","date":"2025-05-19"},{"id":"aadc23fada3301622848143fa53ec4c00b237ef5","name":"The Events Calendar <= 6.11.2.1 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-61121-missing-authorization","description":"The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax_preview_import() function in versions up to, and including, 6.11.2.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to create an import.","date":"2025-05-19"},{"id":"EUVD-2025-28166","name":"EUVD-2025-28166","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-28166","description":"Missing Authorization vulnerability in The Events Calendar The Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Events Calendar: from n\/a through 6.11.2.1.","date":"2025-05-19"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"low","exploitable":null,"impact":null},"epss":"0.001"}},{"uuid":"3468cd59a996b66af5c427d2dce6b7f31d2c0f165ad5f444570ec3b5a7c079c8","name":"The Events Calendar [the-events-calendar] < 6.13.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.13.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-5144","name":"The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-5144","description":"The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018data-date-*\u2019 parameters in all versions up to, and including, 6.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"4fb731a94777c7a76dcc26c3b9b28622575b2f72","name":"The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-6132-authenticated-contributor-dom-based-stored-cross-site-scripting","description":"The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018data-date-*\u2019 parameters in all versions up to, and including, 6.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-06-10"},{"id":"EUVD-2025-18097","name":"EUVD-2025-18097","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-18097","description":"The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018data-date-*\u2019 parameters in all versions up to, and including, 6.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-06-11"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"cc1a28f2547c7c55669bdb196a1a4638dc045d58b55d88f484a8d27ede9cf75c","name":"The Events Calendar [the-events-calendar] < 6.15.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.15.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-12175","name":"CVE-2025-12175","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-12175","description":"[en] The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'tec_qr_code_modal' AJAX endpoint in all versions up to, and including, 6.15.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view draft event names and generate\/view QR codes for them.","date":"2025-10-31"},{"id":"9ffec3061f0db7ab4e15716a9b03385dea0a320a","name":"The Events Calendar <= 6.15.9 - Missing Authorization to Authenticated (Subscriber+) Draft Event Title\/QR Code Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-6159-missing-authorization-to-authenticated-subscriber-draft-event-titleqr-code-exposure","description":"The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'tec_qr_code_modal' AJAX endpoint in all versions up to, and including, 6.15.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view draft event names and generate\/view QR codes for them.","date":"2025-10-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"28a7967896063769846e53b18d45cc85e1711987ac8a88cfef5b1e1fba4d479d","name":"The Events Calendar [the-events-calendar] < 6.15.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.15.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-12192","name":"CVE-2025-12192","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-12192","description":"[en] The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.9. The sysinfo REST endpoint compares the provided key to the stored opt-in key using a loose comparison, allowing unauthenticated attackers to send a boolean value and obtain the full system report whenever \"Yes, automatically share my system information with The Events Calendar support team\" setting is enabled.","date":"2025-11-05"},{"id":"bf98a57f995475611dc5900fd1a9a5bcabeb8553","name":"The Events Calendar <= 6.15.9 - Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-6159-sysinfo-key-incorrect-comparison-to-unauthenticated-sensitive-information-exposure","description":"The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.9. The sysinfo REST endpoint compares the provided key to the stored opt-in key using a loose comparison, allowing unauthenticated attackers to send a boolean value and obtain the full system report whenever \"Yes, automatically share my system information with The Events Calendar support team\" setting is enabled.","date":"2025-11-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-697","name":"Incorrect Comparison","description":"The product compares two entities in a security-relevant context, but the comparison is incorrect."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"18c75b5beb6f371c3041f62caae2ecf94c6b91c3f43912059295cf42351c7ddb","name":"The Events Calendar [the-events-calendar] < 6.15.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.15.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-12197","name":"CVE-2025-12197","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-12197","description":"[en] The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15.1.1 to 6.15.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2025-11-05"},{"id":"ed0a9414b6e7a39d0f8bc9d81a5d719201bad72c","name":"The Events Calendar 6.15.1.1 - 6.15.9 - Unauthenticated SQL Injection via s","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-61511-6159-unauthenticated-sql-injection-via-s","description":"The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15.1.1 to 6.15.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2025-11-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2e665139d51707c560d0134627dbc4e445355a1d8db628092d3ed499401457fa","name":"The Events Calendar [the-events-calendar] < 6.15.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.15.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-69352","name":"CVE-2025-69352","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-69352","description":"[en] Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n\/a through <= 6.15.12.2.","date":"2026-01-06"},{"id":"09f8aca27073698a70dd4b5051a15faa062f639b","name":"The Events Calendar <= 6.15.12.2 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-615122-missing-authorization","description":"The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.15.12.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.","date":"2026-01-09"},{"id":"EUVD-2026-0955","name":"EUVD-2026-0955","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-0955","description":"Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n\/a through <= 6.15.12.2.","date":"2026-01-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"2.8","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"2.8","impact":"2.5"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"97309696e9e90660fd6b72ba8c38da3a94ca204ec034819c6b43eb2836ec824a","name":"The Events Calendar [the-events-calendar] < 6.15.13.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.15.13.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-15043","name":"CVE-2025-15043","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-15043","description":"[en] The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'start_migration', 'cancel_migration', and 'revert_migration' functions in all versions up to, and including, 6.15.13. This makes it possible for authenticated attackers, with subscriber level access and above, to start, cancel, or revert the Custom Tables V1 database migration, including dropping the custom database tables entirely via the revert action.","date":"2026-01-20"},{"id":"d59b35c475f209bc94a7db2a6a1ce1a9009f690b","name":"The Events Calendar <= 6.15.13 - Missing Authorization to Authenticated (Subscriber+) Data Migration Control","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-61513-missing-authorization-to-authenticated-subscriber-data-migration-control","description":"The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'start_migration', 'cancel_migration', and 'revert_migration' functions in all versions up to, and including, 6.15.13. This makes it possible for authenticated attackers, with subscriber level access and above, to start, cancel, or revert the Custom Tables V1 database migration, including dropping the custom database tables entirely via the revert action.","date":"2026-01-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"2.8","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"2.8","impact":"2.5"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"050b928d2a66c6cd20969467f8bf4f79aa0784ed291dde0beb022700dbf7d691","name":"The Events Calendar [the-events-calendar] < 6.15.17.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.15.17.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-3585","name":"The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_import","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-3585","description":"The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.17 via the 'ajax_create_import' function. This makes it possible for authenticated attackers, with Author-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.","date":"0000-00-00"},{"id":"bf7b09371db1f4e7b3e1f9651f34fb2f6824754e","name":"The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_import","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-61517-authenticated-author-arbitrary-file-read-via-ajax-create-import","description":"The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.17 via the 'ajax_create_import' function. This makes it possible for authenticated attackers, with Author-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.","date":"2026-03-09"}],"impact":{"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6dbd71971ce788124bef7210005e4a7715cc0b651a4626c0517073f219d347e0","name":"The Events Calendar [the-events-calendar] < 6.15.16.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.15.16.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-2694","name":"The Events Calendar <= 6.15.16 - Improper Authorization to Authenticated (Contributor+) Event\/Organizer\/Venue Update\/Trash via REST API","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-2694","description":"The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to an improper capability check on the 'can_edit' and 'can_delete' function in all versions up to, and including, 6.15.16. This makes it possible for authenticated attackers, with Contributor-level access and above, to update or trash events, organizers and venues via REST API.","date":"0000-00-00"},{"id":"f7bda285c287769f414770ff5a182d9e3fe48a34","name":"The Events Calendar <= 6.15.16 - Improper Authorization to Authenticated (Contributor+) Event\/Organizer\/Venue Update\/Trash via REST API","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-61516-improper-authorization-to-authenticated-contributor-eventorganizervenue-updatetrash-via-rest-api","description":"The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to an improper capability check on the 'can_edit' and 'can_delete' function in all versions up to, and including, 6.15.16. This makes it possible for authenticated attackers, with Contributor-level access and above, to update or trash events, organizers and venues via REST API.","date":"2026-02-25"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"488e2574e9ff7bba97052cb2cfc62a14250a53a43108e2249936e83a06308d63","name":"The Events Calendar [the-events-calendar] < 6.15.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.15.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-9807","name":"The Events Calendar <= 6.15.1 -  Unauthenticated SQL Injection","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-9807","description":"The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the \u2018s\u2019 parameter in all versions up to, and including, 6.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"0000-00-00"},{"id":"0f0cc86c5b907bbedeeb6c2702bb32818b37a68d","name":"The Events Calendar <= 6.15.1 -  Unauthenticated SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-6151-unauthenticated-sql-injection","description":"The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the \u2018s\u2019 parameter in all versions up to, and including, 6.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2025-09-11"},{"id":"EUVD-2025-29002","name":"EUVD-2025-29002","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-29002","description":"The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the \u2018s\u2019 parameter in all versions up to, and including, 6.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2025-09-12"}],"impact":{"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":null,"impact":null},"epss":"0.001"}},{"uuid":"bd61a4b21171b45898eb6689790f18a8b6428dd487ac5c35fc448c1bad0a0a19","name":"The Events Calendar [the-events-calendar] < 6.15.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.15.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-9808","name":"The Events Calendar <= 6.15.2 - Missing Authorization to Unauthenticated Password-Protected Information Disclosure","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-9808","description":"The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract information about password-protected vendors or venues.","date":"0000-00-00"},{"id":"e6b8947e9e986867da75ae482c00656a8b3ec113","name":"The Events Calendar <= 6.15.2 - Missing Authorization to Unauthenticated Password-Protected Information Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-6152-missing-authorization-to-unauthenticated-password-protected-information-disclosure","description":"The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract information about password-protected vendors or venues.","date":"2025-09-15"},{"id":"EUVD-2025-29359","name":"EUVD-2025-29359","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-29359","description":"The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract information about password-protected vendors or venues.","date":"2025-09-16"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":null,"impact":null}}},{"uuid":"12048f2ac6b4da59712075420c1984662d02d36a77b36026730d5c3da0106425","name":"The Events Calendar [the-events-calendar] < 6.16.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.16.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-49772","name":"CVE-2026-49772","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-49772","description":"[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web \/ StellarWP The Events Calendar allows Blind SQL Injection.\n\nThis issue affects The Events Calendar: from 6.15.12 through 6.16.2.","date":"2026-06-16"},{"id":"ca0f4af97cb7d168637d17d6282e4a5caed64f28","name":"The Events Calendar  6.15.12-6.16.2 - Unauthenticated SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-61512-6162-unauthenticated-sql-injection","description":"The The Events Calendar plugin for WordPress is vulnerable to SQL Injection in versions up to 6.15.12-6.16.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-06-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:H\/I:N\/A:L","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"h","i":"n","a":"l","score":"9.3","severity":"c","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:H\/I:N\/A:L","score":"9.3","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"high","i":"none","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4299f237343d1d405f79461301d92330fabc6c37c5bfcb3a5f3b9eb9d5d49e40","name":"The Events Calendar [the-events-calendar] < 6.16.5.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.16.5.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-13390","name":"The Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Status Manipulation","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-13390","description":"The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arbitrary content in a hidden comment record.","date":"0000-00-00"},{"id":"86a8ce25f8697ef425b0cfdfa8d5edf2da3c41c3","name":"The Events Calendar <= 6.16.5.0 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-61650-missing-authorization","description":"The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.16.5.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-07-06"}],"impact":{"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d7df9c1d393c11739a9d711720c97ea6bf9def006eac6da0ab90f83772bbb4db","name":"The Events Calendar [the-events-calendar] < 6.17.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.17.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-78265","name":"CVE-2026-78265","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-78265","description":"[en] Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.","date":"2026-08-24"},{"id":"EUVD-2026-65172","name":"EUVD-2026-65172","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-65172","description":"Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.","date":"2026-08-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"f737592a58a7033a0d02a8ee5559e46041b1d6810220d1032b6267e9b2e2f144","name":"The Events Calendar [the-events-calendar] < 6.17.3.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.17.3.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-84745","name":"CVE-2026-84745","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-84745","description":"[en] The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with a low-privilege role such as contributor to read the full contents of every unpublished record on the site, including other users'.","date":"2026-09-05"},{"id":"f73500ea381cec08827646045b750c33c8e62f3e","name":"The Events Calendar < 6.17.3.1 - Authenticated (Contributor+) Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-61731-authenticated-contributor-information-exposure","description":"The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 6.17.3.1. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive user or configuration data.","date":"2026-08-24"}],"impact":{"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"1310999c3ee47c0851c30c078f46093008c76ccf4ee086696f3a3ce4722193ea","name":"The Events Calendar [the-events-calendar] < 6.17.4.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.17.4.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-78006","name":"CVE-2026-78006","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-78006","description":"[en] The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attribute before unserialize() is reached. This makes it possible for unauthenticated attackers to execute code on the server. This is exploitable without authentication or approval because the plugin's V2 single-event template runs do_blocks() over buffered comment HTML, and WordPress returns a moderation-hash URL that allows an unauthenticated commenter to immediately view their own pending comment, delivering the injected block markup to the vulnerable code path before any moderation occurs. This does require comments to be enabled and visible on events.","date":"2026-09-12"},{"id":"dc799d67d8f72bdf09c92111d16d18c1dd80d8cc","name":"The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-6174-unauthenticated-php-object-injection-to-remote-code-execution","description":"The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attribute before unserialize() is reached. This makes it possible for unauthenticated attackers to execute code on the server. This is exploitable without authentication or approval because the plugin's V2 single-event template runs do_blocks() over buffered comment HTML, and WordPress returns a moderation-hash URL that allows an unauthenticated commenter to immediately view their own pending comment, delivering the injected block markup to the vulnerable code path before any moderation occurs. This does require comments to be enabled and visible on events.","date":"2026-09-11"},{"id":"EUVD-2026-76832","name":"EUVD-2026-76832","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-76832","description":"The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attribute before unserialize() is reached. This makes it possible for unauthenticated attackers to execute code on the server. This is exploitable without authentication or approval because the plugin's V2 single-event template runs do_blocks() over buffered comment HTML, and WordPress returns a moderation-hash URL that allows an unauthenticated commenter to immediately view their own pending comment, delivering the injected block markup to the vulnerable code path before any moderation occurs. This does require comments to be enabled and visible on events.","date":"2026-09-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null},"epss":"0.008"}},{"uuid":"663cb6ac73aa240520a7897ff9ceb97f5dd6bbab92e4cfc24a48c4b0f4125688","name":"The Events Calendar [the-events-calendar] < 6.17.3.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.17.3.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-78159","name":"CVE-2026-78159","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-78159","description":"[en] The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the targeted site has comments enabled on tribe_events posts and that at least one comment containing a crafted wp:legacy-widget block has been submitted, as the attack chain is triggered when do_blocks() processes the single-event HTML including the comment area.","date":"2026-09-12"},{"id":"0c2cb7fc2fea2bcaee22616f94107ca08e0c700b","name":"The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-6173-unauthenticated-code-injection-to-remote-code-execution-via-widget-classes-map-callable-invocation","description":"The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the targeted site has comments enabled on tribe_events posts and that at least one comment containing a crafted wp:legacy-widget block has been submitted, as the attack chain is triggered when do_blocks() processes the single-event HTML including the comment area.","date":"2026-09-11"},{"id":"EUVD-2026-76833","name":"EUVD-2026-76833","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-76833","description":"The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the targeted site has comments enabled on tribe_events posts and that at least one comment containing a crafted wp:legacy-widget block has been submitted, as the attack chain is triggered when do_blocks() processes the single-event HTML including the comment area.","date":"2026-09-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-94","name":"Improper Control of Generation of Code ('Code Injection')","description":"The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null},"epss":"0.008"}}]},"updated":"1789280274"}