N/A
2026-02-17< 1.5.8
Community Events <= 1.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'ce_venue_name' Parameter
Minimum safe version
1.5.9
Update to 1.5.9 or later to address 15 fixable vulnerabilities
Community Events <= 1.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'ce_venue_name' Parameter
Community Events <= 1.5.8 - Authenticated (Administrator+) SQL Injection via 'ce_venue_name' CSV Field
CVE-2025-14029
CVE-2025-12646
CVE-2025-11995
CVE-2025-10587
CVE-2025-10586
CVE-2024-6270
CVE-2024-6271
CVE-2022-44742
Community Events <= 1.2.1 - SQL Injection
WordPress Community Events Plugin 1.3.5 - SQL Injection
WordPress Community Events Plugin <= 1.2.1 - SQL Injection
CVE-2015-3313
CVE-2021-24496