The Events Calendar <= 6.15.2 - Missing Authorization to Unauthenticated Password-Protected Information Disclosure
The Events Calendar
Minimum safe version
6.15.17.1
Update to 6.15.17.1 or later to address 43 fixable vulnerabilities
The Events Calendar <= 6.15.1 - Unauthenticated SQL Injection
The Events Calendar <= 6.15.16 - Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API
The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_import
CVE-2025-15043
The Events Calendar <= 6.15.12.2 - Missing Authorization
CVE-2025-12197
CVE-2025-12192
CVE-2025-12175
The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
CVE-2025-48246
CVE-2025-24537
CVE-2024-12118
CVE-2024-5333
Freemius SDK <= 2.4.2 - Missing Authorization Checks
The Events Calendar <= 6.6.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
CVE-2024-8275
CVE-2024-6931
CVE-2024-37518
CVE-2024-1295
CVE-2024-4180
CVE-2024-31433
CVE-2023-6557
CVE-2023-6203
WordPress The Events Calendar Plugin < 6.2.8.1 is vulnerable to Sensitive Data Exposure
The Events Calendar <= 6.2.8 - Information Disclosure
The Events Calendar < 5.14.0 - Reflected Cross-Site Scripting
The Events Calendar <= 3.0 - Reflected Cross-Site Scripting (XSS)
The Events Calendar <= 4.1.1 - Open Redirect
WordPress The Events Calendar Plugin < 5.14.0.4 is vulnerable to Sensitive Data Exposure
WordPress The Events Calendar Plugin < 5.14.0.4 is vulnerable to Cross Site Request Forgery (CSRF)
WordPress The Events Calendar Plugin <= 4.1.1 is vulnerable to Open Redirection
WordPress The Events Calendar Plugin <= 3.0 is vulnerable to Cross Site Scripting (XSS)
WordPress The Events Calendar Plugin <= 6.0.13.1 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-35777
The Events Calendar < 4.1.1.1 - Open Redirect
Freemius SDK <= 2.4.2 - Missing Authorization Checks
Unauthorised AJAX Calls via Freemius
WordPress The Events Calendar Plugin <= 3.0 - Reflected Cross Site Scripting
WordPress The Events Calendar Plugin <= 4.1.1 - Open Redirection
WordPress The Events Calendar plugin < 5.14.0.4 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
WordPress The Events Calendar plugin < 5.14.0.4 - Sensitive Information Disclosure vulnerability
CVE-2019-15109