Stellarwp
Stellarwp THE Events Calendar: vulnerabilidades y CVE
Stellarwp THE Events Calendar tiene 15 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses2
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-49772 | Crítica (9.3) | 0.45% | — | 16 jun 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from… |
| CVE-2025-69352 | Media (5.4) | 0.20% | — | 6 ene 2026 | Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through… |
| CVE-2025-5144 | Media (5.4) | 0.26% | — | 11 jun 2025 | The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, 6.13.2 due to insufficient input sanitization and output… |
| CVE-2025-48246 | Media (5.4) | 0.36% | — | 19 may 2025 | Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through… |
| CVE-2024-8493 | Media (4.8) | 0.35% | — | 15 may 2025 | The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2025-24537 | Media (5.4) | 0.16% | — | 27 ene 2025 | Cross-Site Request Forgery (CSRF) vulnerability in StellarWP The Events Calendar the-events-calendar allows Cross Site Request Forgery.This issue affects The Events Calendar: from n/a through <= 6.7.0. |
| CVE-2024-37518 | Media (4.3) | 0.19% | — | 2 ene 2025 | Cross-Site Request Forgery (CSRF) vulnerability in StellarWP The Events Calendar the-events-calendar allows Cross Site Request Forgery.This issue affects The Events Calendar: from n/a through <= 6.5.1.4. |
| CVE-2024-5333 | Media (5.3) | 1.1% | — | 16 dic 2024 | The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events. |
| CVE-2024-6931 | Media (6.1) | 17% | — | 27 sept 2024 | The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6.6.3 due to insufficient input sanitization and output escaping. This… |
| CVE-2024-8275 | Crítica (9.8) | 50% | — | 25 sept 2024 | The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on… |
| CVE-2024-4180 | Crítica (9.1) | 1.8% | — | 4 jun 2024 | The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX. |
| CVE-2024-31433 | Media (4.3) | 0.20% | — | 15 abr 2024 | Cross-Site Request Forgery (CSRF) vulnerability in StellarWP The Events Calendar the-events-calendar.This issue affects The Events Calendar: from n/a through <= 6.3.0. |
| CVE-2023-6557 | Media (5.3) | 0.56% | — | 5 feb 2024 | The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it… |
| CVE-2023-6203 | Alta (7.5) | 0.78% | — | 18 dic 2023 | The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request |
| CVE-2019-15109 | Media (6.1) | 1.1% | — | 21 ago 2019 | The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.