Skip to main content

Software intelligence

The Events Calendar vulnerabilities

30 tracked advisories · slug the-events-calendar

Important: The Events Calendar appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works

Tracked advisories

30

Latest advisory

6 July 2026

CISA KEV matches

0

In this WordPress feed

WordPress slug

the-events-calendar

Plugin

What this means for The Events Calendar

This catalog lists 30 known advisories affecting The Events Calendar. The most recent was published on 6 July 2026. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.

Latest issues

  • The Events Calendar <= 6.16.5.0 - Missing Authorization

    This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.

    Published 6 July 2026

  • The Events Calendar 6.15.12-6.16.2 - Unauthenticated SQL Injection

    May allow attackers to read or modify database contents beyond intended access.

    Published 8 June 2026

  • The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_import

    This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.

    Published 9 March 2026

Vulnerability types

  • Cross-site scripting7
  • SQL injection4
  • CSRF3

Authentication (inferred from titles)

  • Unauthenticated9
  • Authenticated8
  • Unspecified13

Advisory history

Known The Events Calendar advisories published by month.

All advisories

115 of 30

1 / 2

Check whether your installed version is affected

SiteRespond Defence matches your installed The Events Calendar version against this catalog when the Defence plugin is connected to your WordPress site.