Input validation vulnerability in The Events Calendar 6.15.9

The Events Calendar plugin for WordPress has a security weakness that allows hackers to inject malicious code into the ‘s’ parameter. This can happen in versions 6.15.1.1 to 6.15.9 because the plugin does not properly protect against this type of attack. This means that attackers can potentially access confidential information from the database without needing to log in.

Detected in:

The Events Calendar fixed vulnerable versions: >= 6.15.1.1 <= 6.15.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.