Theeventscalendar
Theeventscalendar THE Events Calendar: vulnerabilidades y CVE
Theeventscalendar THE Events Calendar tiene 19 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE19
Últimos 12 meses15
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-84740 | Media (6.5) | 0.22% | — | 2 oct 2026 | The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it into its rendering context, allowing unauthenticated users to execute… |
| CVE-2026-97285 | Media (5.4) | 0.20% | — | 30 sept 2026 | Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions. |
| CVE-2026-84743 | Baja (3.8) | 0.23% | — | 23 sept 2026 | The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with a low-privilege role such as contributor to modify,… |
| CVE-2026-84741 | Media (5.3) | 0.25% | — | 23 sept 2026 | The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST API response, allowing unauthenticated users to read the… |
| CVE-2026-78159 | Crítica (9.8) | 1.4% | — | 12 sept 2026 | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget… |
| CVE-2026-78006 | Crítica (9.8) | 1.5% | — | 12 sept 2026 | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in… |
| CVE-2026-84745 | Baja (2.7) | 0.32% | — | 5 sept 2026 | The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with a low-privilege role such as contributor to… |
| CVE-2026-78265 | Crítica (9.8) | 0.56% | — | 24 ago 2026 | Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions. |
| CVE-2026-13390 | Media (5.3) | 0.30% | — | 27 jul 2026 | The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing… |
| CVE-2025-69135 | Alta (8.5) | 0.34% | — | 17 jun 2026 | Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions. |
| CVE-2026-3585 | Alta (7.5) | 0.53% | — | 10 mar 2026 | The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.17 via the 'ajax_create_import' function. This makes it possible for authenticated attackers, with… |
| CVE-2025-15043 | Media (5.4) | 0.21% | — | 20 ene 2026 | The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'start_migration', 'cancel_migration', and 'revert_migration' functions in all versions up to,… |
| CVE-2025-12192 | Media (5.3) | 0.27% | — | 5 nov 2025 | The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.9. The sysinfo REST endpoint compares the provided key to the stored opt-in key using a loose… |
| CVE-2025-12197 | Alta (7.5) | 18% | — | 5 nov 2025 | The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15.1.1 to 6.15.9 due to insufficient escaping on the user supplied parameter and lack of sufficient… |
| CVE-2025-12175 | Media (4.3) | 0.24% | — | 31 oct 2025 | The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'tec_qr_code_modal' AJAX endpoint in all versions up to, and including, 6.15.9. This makes it… |
| CVE-2025-9808 | Media (5.3) | 0.83% | — | 16 sept 2025 | The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract… |
| CVE-2025-9807 | Alta (7.5) | 0.35% | — | 12 sept 2025 | The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all versions up to, and including, 6.15.1 due to insufficient escaping on the user supplied parameter and… |
| CVE-2024-12118 | Media (5.4) | 0.29% | — | 23 ene 2025 | The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget through the html_tag attribute in all versions up to, and including, 6.9.0 due to insufficient… |
| CVE-2023-35777 | Media (5.3) | 0.63% | — | 13 dic 2024 | Missing Authorization vulnerability in The Events Calendar The Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through 6.1.2.2. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.