VendorsStellarWPthe_events_calendarall versions
Vulnerabilities

StellarWP The Events Calendar

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2024-8275
The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection
Published 2024-09-25 · Analyzed
9.8EPSS 0.499
CVE-2024-4180
The Events Calendar < 6.4.0.1 - Reflected XSS
Published 2024-06-04 · Analyzed
9.1EPSS 0.018
CVE-2023-6203
The Events Calendar < 6.2.8.1 - Unauthenticated Arbitrary Password Protected Post Read
Published 2023-12-18 · Modified
7.5EPSS 0.008
CVE-2024-6931
The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site Scripting
Published 2024-09-27 · Analyzed
7.2EPSS 0.167
CVE-2025-5144
The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
Published 2025-06-11 · Analyzed
6.4EPSS 0.003
CVE-2019-15109
The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.
Published 2019-08-21 · Modified
6.1EPSS 0.011
CVE-2024-5333
The Events Calendar < 6.8.2.1 - Unauthenticated Password Protected Event Disclosure
Published 2024-12-16 · Analyzed
5.3EPSS 0.011
CVE-2023-6557
The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposure
Published 2024-02-05 · Modified
5.3EPSS 0.006
CVE-2024-8493
The Events Calendar < 6.6.4 - Admin+ Stored XSS
Published 2025-05-15 · Analyzed
4.8EPSS 0.003