« Volver al listado

Theeventscalendar

Theeventscalendar THE Events Calendar: vulnerabilidades y CVE

Theeventscalendar THE Events Calendar tiene 19 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE19
Últimos 12 meses15
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-84740Media (6.5)0.22%—2 oct 2026
The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it into its rendering context, allowing unauthenticated users to execute…
CVE-2026-97285Media (5.4)0.20%—30 sept 2026
Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions.
CVE-2026-84743Baja (3.8)0.23%—23 sept 2026
The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with a low-privilege role such as contributor to modify,…
CVE-2026-84741Media (5.3)0.25%—23 sept 2026
The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST API response, allowing unauthenticated users to read the…
CVE-2026-78159Crítica (9.8)1.4%—12 sept 2026
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget…
CVE-2026-78006Crítica (9.8)1.5%—12 sept 2026
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in…
CVE-2026-84745Baja (2.7)0.32%—5 sept 2026
The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with a low-privilege role such as contributor to…
CVE-2026-78265Crítica (9.8)0.56%—24 ago 2026
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
CVE-2026-13390Media (5.3)0.30%—27 jul 2026
The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing…
CVE-2025-69135Alta (8.5)0.34%—17 jun 2026
Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions.
CVE-2026-3585Alta (7.5)0.53%—10 mar 2026
The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.17 via the 'ajax_create_import' function. This makes it possible for authenticated attackers, with…
CVE-2025-15043Media (5.4)0.21%—20 ene 2026
The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'start_migration', 'cancel_migration', and 'revert_migration' functions in all versions up to,…
CVE-2025-12192Media (5.3)0.27%—5 nov 2025
The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.9. The sysinfo REST endpoint compares the provided key to the stored opt-in key using a loose…
CVE-2025-12197Alta (7.5)18%—5 nov 2025
The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15.1.1 to 6.15.9 due to insufficient escaping on the user supplied parameter and lack of sufficient…
CVE-2025-12175Media (4.3)0.24%—31 oct 2025
The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'tec_qr_code_modal' AJAX endpoint in all versions up to, and including, 6.15.9. This makes it…
CVE-2025-9808Media (5.3)0.83%—16 sept 2025
The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract…
CVE-2025-9807Alta (7.5)0.35%—12 sept 2025
The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all versions up to, and including, 6.15.1 due to insufficient escaping on the user supplied parameter and…
CVE-2024-12118Media (5.4)0.29%—23 ene 2025
The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget through the html_tag attribute in all versions up to, and including, 6.9.0 due to insufficient…
CVE-2023-35777Media (5.3)0.63%—13 dic 2024
Missing Authorization vulnerability in The Events Calendar The Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through 6.1.2.2.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application8
  2. T1005 Data from Local System5
  3. T1059 Command and Scripting Interpreter4
  4. T1210 Exploitation of Remote Services3
  5. T1078 Valid Accounts1
  6. T1078.002 Domain Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Theeventscalendar