SecAlerts
t

the events calendar

Security Risk Profile

39
/100
low

Security Risk Score

Comprehensive risk assessment based on 19 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from May 17, 2024 to present

19
Total CVEs
4
Critical+High
0
Exploited
4
Unpatched

Threat Assessment

Avg CVSS
6.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
4
Critical/High
Risk Level
39/100
low
🆕 3Fresh (<7d)📈 7 in Last 30 Days

Severity Distribution

Critical
2
High
2
Medium
12
Low
2

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
5

Age Distribution

Common Weaknesses (CWE)

1
XSS
6
2
SQL Injection
3
3
Code Injection
1

Most Affected Products

1. The Events Calendar The Events Calendar10
2. Stellarwp The Events Calendar Wordpress3
3. The Events Calendar Registrations for The Events Calendar2
4. The Events Calendar Event Tickets and Registration1
5. The Events Calendar WordPress plugin The Events Calendar1

Recent Vulnerabilities

See more →
CVE-2026-97634
CVSS 6.5EPSS 0%medium

Event Tickets and Registration <= 5.29.5 - Authenticated (Contributor+) SQL Injection via 'orderby' Parameter

Oct 2, 2026🔧 No Patch
CVE-2026-84740
CVSS 6.5medium

The Events Calendar 6.12.0 - 6.17.5 - Unauthenticated Arbitrary Shortcode Execution via 'view_data' Parameter

Oct 2, 2026🔧 No Patch
CVE-2026-97285
CVSS 5.4EPSS 0%medium

WordPress The Events Calendar plugin <= 6.17.5 - Broken Access Control vulnerability

Sep 30, 2026🔧 No Patch
https://reddit.com/r/cybersecurity/comments/1worpli/landed_my_first_cve_in_a_plugin_with_600k/
unknown

Landed my first CVE !! (in a plugin with 600k+ installs) after months of mostly dead ends. Sharing the actual process, not just the win.

Sep 24, 2026🔧 No Patch
CVE-2026-84742
CVSS 2.7low

The Events Calendar 6.15.0 - 6.17.4.1 - Contributor+ Content Publication via TEC V1 REST API

Sep 23, 2026🔧 No Patch
CVE-2026-84743
CVSS 3.8low

The Events Calendar 6.15.16.1 - 6.17.4.1 - Contributor+ Event/Venue/Organizer Update, Trash and Ownership Takeover via by-slug REST Routes

Sep 23, 2026🔧 No Patch
CVE-2026-78159
CVSS 9.8critical

The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation

Sep 12, 2026🔧 No Patch
CVE-2026-75963
CVSS 7.5high

Events Made Easy <= 3.2.5 - Authenticated (Contributor+) Local File Inclusion via 'wp_page_template' Event Property

Aug 20, 2026🔧 No Patch
CVE-2026-13119
CVSS 6.5medium

Registrations for the Events Calendar <= 3.2 - Authenticated (Contributor+) SQL Injection via 'standard' Parameter

Jul 23, 2026🔧 No Patch
CVE-2025-12192
CVSS 5.3medium

The Events Calendar <= 6.15.9 - Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information Exposure

Nov 5, 2025🔧 No Patch

Monitor the events calendar in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.