The Events Calendar

The Events Calendar has 34 disclosed vulnerabilities in the WordSec catalog, reported between 2016 and 2026; all 34 are fixed as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 9.8 out of 10. Severity breakdown: 3 critical and 6 high. 2026 was the busiest year with 10 disclosures.

The most common weakness is Missing Authorization, behind 9 of the records (26%). Other recurring categories include Cross-Site Scripting, SQL Injection.

Every one of the 34 issues recorded for The Events Calendar has a vendor fix available, so running the current release closes all known holes.

26 independent researchers contributed these findings, most of them (3) reported by Rafie Muhammad. The Events Calendar is installed on roughly 600,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

01234567891019.01.2010Today25.04.20164.7The Events Calendar < 4.1.1.1 - Open Redirect CVSS 4.7 · 25.04.201604.03.20196.1The Events Calendar <= 4.8.1 - Cross-Site Scripting via tribe_paged Parameter CVSS 6.1 · 04.03.201904.03.20226.3Freemius SDK <= 2.4.2 - Missing Authorization Checks CVSS 6.3 · 04.03.202218.07.20236.1Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get CVSS 6.1 · 18.07.202325.07.20234.3The Events Calendar <= 6.1.2.2 - Missing Authorization CVSS 4.3 · 25.07.202320.11.20235.3The Events Calendar <= 6.2.8 - Information Disclosure CVSS 5.3 · 20.11.202312.01.20245.3The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposure CVSS 5.3 · 12.01.202410.04.20244.3The Events Calendar <= 6.3.0 - Cross-Site Request Forgery to Notice Dismissal CVSS 4.3 · 10.04.202414.05.20246.1The Events Calendar <= 6.4.0 - Reflected Cross-Site Scripting CVSS 6.1 · 14.05.202424.05.20244.3The Events Calendar Free & Pro <= 6.4.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Events Access CVSS 4.3 · 24.05.202405.07.20244.3The Events Calendar <= 6.5.1.4 - Cross-Site Request Forgery via action_restore_events CVSS 4.3 · 05.07.202423.07.20247.2The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 23.07.202431.07.20244.4The Events Calendar <= 6.6.3 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 31.07.202424.09.20249.8The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection CVSS 9.8 · 24.09.202425.11.20245.3The Events Calendar <= 6.8.2 - Missing Authorization to Unauthenticated Password Protected Event Disclosure CVSS 5.3 · 25.11.202409.01.20254.3The Events Calendar <= 6.7.0 - Cross-Site Request Forgery CVSS 4.3 · 09.01.202522.01.20256.4The Events Calendar <= 6.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 22.01.202519.05.20254.3The Events Calendar <= 6.11.2.1 - Missing Authorization CVSS 4.3 · 19.05.202510.06.20256.4The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting CVSS 6.4 · 10.06.202511.09.20257.5The Events Calendar <= 6.15.1 - Unauthenticated SQL Injection CVSS 7.5 · 11.09.202515.09.20255.3The Events Calendar <= 6.15.2 - Missing Authorization to Unauthenticated Password-Protected Information Disclosure CVSS 5.3 · 15.09.202530.10.20254.3The Events Calendar <= 6.15.9 - Missing Authorization to Authenticated (Subscriber+) Draft Event Title/QR Code Exposure CVSS 4.3 · 30.10.202504.11.20257.5The Events Calendar 6.15.1.1 - 6.15.9 - Unauthenticated SQL Injection via s CVSS 7.5 · 04.11.20255.3The Events Calendar <= 6.15.9 - Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information Exposure CVSS 5.3 · 04.11.202509.01.20264.3The Events Calendar <= 6.15.12.2 - Missing Authorization CVSS 4.3 · 09.01.202620.01.20265.4The Events Calendar <= 6.15.13 - Missing Authorization to Authenticated (Subscriber+) Data Migration Control CVSS 5.4 · 20.01.202625.02.20265.4The Events Calendar <= 6.15.16 - Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API CVSS 5.4 · 25.02.202609.03.20267.5The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_import CVSS 7.5 · 09.03.202608.06.20267.5The Events Calendar 6.15.12-6.16.2 - Unauthenticated SQL Injection CVSS 7.5 · 08.06.202606.07.20265.3The Events Calendar <= 6.16.5.0 - Missing Authorization CVSS 5.3 · 06.07.202624.08.20268.1The Events Calendar <= 6.17.2 - Unauthenticated PHP Object Injection CVSS 8.1 · 24.08.202605.09.20264.3The Events Calendar < 6.17.3.1 - Authenticated (Contributor+) Information Exposure CVSS 4.3 · 05.09.202611.09.20269.8The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution CVSS 9.8 · 11.09.20269.8The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation CVSS 9.8 · 11.09.2026

Strategic Overview

Avg CVSSMedium
6.0/ 10
Patch Coverage100%
Open

0

Fixed

34

Get automatic notifications for all The Events Calendar vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2026-78159

The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation

Read the full analysis

Vulnerability Records

34 records
2026-09-11 18:40CVE-2026-78159
9.8
Critical
Chloe ChamberlandYes
2026-09-11 18:39CVE-2026-78006
9.8
Critical
Chloe ChamberlandYes
2026-09-05 00:00CVE-2026-84745
4.3
Medium
Mohammed Abd AlrahmanYes
2026-08-24 12:30CVE-2026-78265
8.1
High
Udin ChanYes
2026-07-06 00:00CVE-2026-13390
5.3
Medium
Haitam LazaarYes
2026-06-08 00:00CVE-2026-49772
7.5
High
vtimYes
2026-03-09 14:40CVE-2026-3585
7.5
High
Dmitrii IgnatyevYes
2026-02-25 08:50CVE-2026-2694
5.4
Medium
type5afeYes
2026-01-20 01:45CVE-2025-15043
5.4
Medium
type5afeYes
2026-01-09 00:00CVE-2025-69352
4.3
Medium
Phat RiOYes
Showing 1–10 of 34 reports
The Events Calendar banner
Latestv6.17.4.1

The Events Calendar

Nexcess

Author

Nexcess

4.2(2,454)
84/100
Last Updated
2026-09-10 (2d ago)
Active Installs
600,000+
Downloads
86,602,391
Requires WP
6.7+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2010-01-19 (17y ago)

Easily create and manage an events calendar on your WordPress site with The Events Calendar free plugin. Whether your events are in-person or virtual events, this WordPress calendar plugin boasts professional features backed by our world-class team of developers and designers. See more videos on our YouTube channel Packed with loads of features, The Events Calendar is ready to go out of the box. It’s also extensible, easy to use, and completely customizable. 📅 The #1 Calendar for WordPress See the calendar in action on our demo experience. Just getting started? Read through the New User Primer to get set up. Looking for additional features like recurring events, ticket sales, user-submitted events, automatic imports, and more? Check out Events Calendar Pro, Event Aggregator, and more add-ons. 🔌🎨 Plug and Play or Customize The Events Calendar is built to work out of the box. Simply install the plugin, configure your settings, and start creating events in minutes. Want to add your personal touch? Use The Events Calendar as the foundation for customization. Personalize to your heart’s content with the help of a skeleton stylesheet, partial template overrides, template tags, hooks and filters, careful documentation, and a library of free extensions. Whether your vision is big or small, you’re in good company. Hundreds of thousands of small businesses, musicians, venues, restaurants, and non-profits are publishing and promoting their in-person and virtual events with The Events Calendar. Our plugins have also been scaled to work on large networks for Fortune 100 companies, universities, and government institutions. ✨ Features Our feature-rich plugin comes with everything you need to create and manage your calendar. ✔️ Rapidly create events ✔️ Saved venues & organizers ✔️ Calendar month view with tooltips ✔️ Event List view ✔️ Day view ✔️ Block Editor support ✔️ Event search ✔️ Google maps ✔️ Widget: Upcoming events list ✔️ Events Taxonomies (Categories & Tags) ✔️ Google Calendar and iCal exporting ✔️ WP REST API endpoints ✔️ Completely ajaxified for super smooth browsing ✔️ Completely responsive from mobile to tablet to desktop ✔️ Tested on the major theme frameworks such as Avada, Divi, Enfold, Genesis, and many more. ✔️ Increase your SEO with JSON-LD Structured Data ✔️ Internationalized & translated ✔️ Multiple stylesheets to improve integration ✔️ Extensive template tags for customization ✔️ Hooks & filters galore ✔️ Caching support ✔️ Debug mode for developers ✔️ Library of extensions 📃 Documentation All of our documentation can be found in our Knowledgebase. Additional helpful links: The Events Calendar New User Primer The Themer’s Guide to The Events Calendar If you have any questions about this plugin, you can post a thread in the WordPress.org forum. Please search existing threads before starting a new one. Add-Ons Take your calendar to the next level by pairing it with our plugins for ticketing, crowdsourcing, email marketing, and more. Learn more about all our products on our website. Our Free Plugins: 🎟️ Event Tickets 📐 Advanced Post Manager Our Premium Plugins and Services: ⚡ Events Calendar PRO ↪️ Event Aggregator (service) 🎟️ Event Tickets Plus ✉️ Promoter 👥 Community Events ✏️ Filter Bar 🗓️ Eventbrite Tickets Help If you aren’t familiar with The Events Calendar, check out our New User Primer. It will have you creating events in no time. Ready to dig deeper? Check out these resources: Tutorials Release Schedule Known Issues Documentation Help Videos Release Notes We check in on the The Events Calendar forum here on WordPress.org about once a week to help users with basic troubleshooting and identifying bugs. If you’re looking for premium, personalized support, consider upgrading to Events Calendar Pro. Still have a question? Shoot us an email at support@theeventscalendar.com.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C