SQL Injection
5 records41.7%First: 2015. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 12 vulnerability records associated with Community Events, published between 2015 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2015 | 1 | |
| 2021 | 1 | |
| 2022 | 1 | |
| 2024 | 2 | |
| 2025 | 4 | |
| 2026 | 3 |
| Severity | Records | Share |
|---|---|---|
| Critical | 3 | 25% |
| High | 2 | 16.7% |
| Medium | 7 | 58.3% |
First: 2015. Latest: 2026.
First: 2021. Latest: 2026.
First: 2024. Latest: 2024.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
1.5.91.5.81.5.71.5.51.5.31.5.21.5.11.51.4.91.4.81.4Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-1.5.8 | Community Events <= 1.5.8 - Authenticated (Administrator+) SQL Injection via 'ce_venue_name' CSV Field | March 6, 2026 | 1.5.9 | Medium |
*-1.5.7 | Community Events <= 1.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'ce_venue_name' Parameter | February 17, 2026 | 1.5.8 | Medium |
*-1.5.6 | Community Events <= 1.5.6 - Missing Authorization to Unauthenticated Arbitrary Event Approval via 'eventlist' Parameter | January 16, 2026 | 1.5.7 | Medium |
*-1.5.4 | Community Events <= 1.5.4 - Unauthenticated SQL Injection | November 18, 2025 | 1.5.5 | High |
*-1.5.2 | Community Events <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting | October 31, 2025 | 1.5.3 | High |
*-1.5.1 | Community Events <= 1.5.1 - Unauthenticated SQL Injection | October 8, 2025 | 1.5.2 | Critical |
*-1.5.1 | Community Events <= 1.5.1 - Unauthenticated SQL Injection | October 7, 2025 | 1.5.2 | Critical |
*-1.5 | Community Events <= 1.5 - Authenticated (Admin+) Stored Cross-Site Scripting | July 15, 2024 | 1.5.1 | Medium |
*-1.4.9 | Community Events <= 1.4.9 - Cross-Site Request Forgery | July 1, 2024 | 1.5 | Medium |
*-1.4.8 | Community Events <= 1.4.8 - Authenticated (Administrator+) Stored Cross Site Scripting | November 25, 2022 | 1.4.9 | Medium |
[*, 1.4.8) | Community Events <= 1.4.7 - Reflected Cross-Site Scripting | July 2, 2021 | 1.4.8 | Medium |
*-1.3 | Community Events < 1.4 - SQL Injection | April 20, 2015 | 1.4 | Critical |
Selected source records
Published: March 6, 2026
Published: February 17, 2026
Published: January 16, 2026
Published: November 18, 2025
Published: October 31, 2025
Published: October 8, 2025
Published: October 7, 2025
Published: July 15, 2024
Published: April 20, 2015
Published: October 8, 2025
Published: October 7, 2025
Published: November 18, 2025
Published: October 31, 2025
Published: July 2, 2021
Published: November 25, 2022
Published: January 16, 2026
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.