The Events Calendar

The Events Calendar is a free WordPress plugin that allows users to create and manage events calendars on their websites. The plugin is easy to use, customizable, and comes with professional features. It is also extensible and can be used as a foundation for customization. Additional features such as recurring events, ticket sales, and user-submitted events can be added with Events Calendar Pro, Event Aggregator, and other add-ons. The plugin can be seen in action on the demo experience and new users can read the New User Primer to get started.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in The Events Calendar 6.9.0

    Fixed

    The Events Calendar plugin for WordPress has a security issue known as Stored Cross-Site Scripting. This means that hackers can insert harmful scripts into the plugin's Event Calendar Link Widget, wh...

    Read More
  • Information leakage vulnerability in The Events Calendar 6.8.2

    Fixed

    The Events Calendar add-on for WordPress has a security flaw that allows anyone to view private information on versions 6.8.2 and below. This happens because the plugin does not have enough restricti...

    Read More
  • Input validation vulnerability in The Events Calendar 6.6.3

    Fixed

    The Events Calendar plugin for WordPress is not secure and can be hacked through the admin settings. This allows attackers with high-level permissions to add harmful scripts to pages that users visit...

    Read More
  • Input validation vulnerability in The Events Calendar 6.6.3

    Fixed

    The Events Calendar plugin for WordPress has a security issue that allows hackers to insert harmful code into pages. This can happen even if the user is not logged in.

    Read More
  • Input validation vulnerability in The Events Calendar 6.6.4

    Fixed

    A popular plugin for WordPress called The Events Calendar has a security issue. This means that someone could potentially access sensitive information from the database by adding additional code to a...

    Read More
  • Input validation vulnerability in The Events Calendar 6.5.1.4

    Fixed

    The Events Calendar plugin for WordPress has a security issue that can be exploited by hackers. This vulnerability, present in versions up to 6.5.1.4, is caused by a lack of proper validation when re...

    Read More
  • Input validation vulnerability in The Events Calendar 6.4.0

    Fixed

    The Events Calendar plugin for WordPress has a security issue that allows hackers to inject harmful web scripts into pages. This can happen if a user is tricked into clicking on a link, and it affect...

    Read More
  • Access violation vulnerability in The Events Calendar 6.4.0

    Fixed

    Many add-ons for WordPress are at risk of being accessed by unauthorized users because they lack proper security measures. This means that attackers with Contributor-level access or higher can view ...

    Read More
  • Input validation vulnerability in The Events Calendar 6.3.0

    Fixed

    The Events Calendar plugin for WordPress has a security issue where unauthorized individuals can trick site administrators into dismissing important notices by sending a fake request. This vulnerabil...

    Read More
  • Access violation vulnerability in The Events Calendar 6.2.8.2

    Fixed

    A popular plugin for WordPress called The Events Calendar has a security issue that affects all versions up to 6.2.8.2. This issue involves a function called "route" that is connected to something ca...

    Read More
  • Information leakage vulnerability in The Events Calendar 6.2.8.1

    Fixed

    The Events Calendar plugin for WordPress is vulnerable to a security risk in all versions up to and including 6.2.8. This risk allows people who are not authenticated users to access sensitive inform...

    Read More
  • Access violation vulnerability in The Events Calendar 6.1.2.2

    Fixed

    The Events Calendar plugin for WordPress is vulnerable to a security issue which could allow unauthorized people to view private event content. Versions up to 6.1.2.2 are affected, due to a missing c...

    Read More
  • Input validation vulnerability in Freemius SDK 2.5.9 (1072 components affected)

    Fixed

    The Freemius SDK for WordPress is vulnerable to an attack known as Reflected Cross-Site Scripting. This attack is possible because of insufficient security measures in versions of the Freemius SDK up ...

    Read More
  • Input validation vulnerability in The Events Calendar 4.1.1

    Fixed

    The Events Calendar plugin for WordPress is not secure in versions before 4.1.1.1. This means that attackers can make links on trusted websites that take people to untrustworthy websites.

    Read More
  • Input validation vulnerability in The Events Calendar 4.8.2

    Fixed

    The Events Calendar plugin

    Read More
  • Access violation vulnerability in Freemius SDK (620 components affected)

    Fixed

    Freemius, a software development kit used by hundreds of WordPress plugin and theme developers, had a security vulnerability in its older versions (up to and including 2.4.2). This vulnerability could...

    Read More