Medium 4.8 Unfixed
2025-05-19≤ 1.0.4
WordPress Event Calendar Plugin <= 1.0.4 is vulnerable to Cross Site Scripting (XSS)
Minimum safe version
6.7.12a
Update to 6.7.12a or later to address 5 fixable vulnerabilities
WordPress Event Calendar Plugin <= 1.0.4 is vulnerable to Cross Site Scripting (XSS)
WordPress Event Single Page Templates Addon For The Events Calendar Plugin < 6.2.8.1 is vulnerable to Sensitive Data Exposure
Events Calendar - wp-admin/admin.php EC_id Parameter XSS
Events Calendar - SQL Injection
WordPress Events Plugin - SQL Injection Vulnerability
CVE-2018-5315