Community Events
Community Events has 12 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2026; all 12 are fixed as of September 2026. Their average CVSS score is 6.6, and the most serious one scores 9.8 out of 10. Severity breakdown: 3 critical and 2 high. 2025 was the busiest year with 4 disclosures.
The most common weakness is Cross-Site Scripting, behind 5 of the records (42%). Other recurring categories include SQL Injection, Cross-Site Request Forgery (CSRF).
Every one of the 12 issues recorded for Community Events has a vendor fix available, so running the current release closes all known holes.
8 independent researchers contributed these findings, most of them (3) reported by ifoundbug. Community Events is installed on roughly 30 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-10586Community Events <= 1.5.1 - Unauthenticated SQL Injection
Read the full analysisVulnerability Records

Community Events
Author
Yannick Lefebvre
The purpose of this plugin is to allow users to create a schedule of upcoming events and display events for the next 7 days in an AJAX-driven box or displaying a full list of upcoming events. You can try it out in a temporary copy of WordPress here.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C