Missing Authorization
11 records36.7%First: 2022. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 30 vulnerability records associated with The Events Calendar, published between 2016 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2016 | 1 | |
| 2019 | 1 | |
| 2022 | 1 | |
| 2023 | 3 | |
| 2024 | 9 | |
| 2025 | 9 | |
| 2026 | 6 |
| Severity | Records | Share |
|---|---|---|
| Critical | 1 | 3.3% |
| High | 5 | 16.7% |
| Medium | 23 | 76.7% |
| Informational | 1 | 3.3% |
First: 2022. Latest: 2026.
First: 2019. Latest: 2025.
First: 2024. Latest: 2026.
First: 2023. Latest: 2025.
First: 2024. Latest: 2025.
First: 2016. Latest: 2016.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
6.16.5.16.16.36.15.17.16.15.16.16.15.13.16.15.136.15.106.15.36.15.1.16.13.2.16.12.06.9.16.7.16.8.2.16.6.4.16.6.46.5.1.56.4.0.16.3.16.2.96.2.8.16.1.35.16.4.15.14.0.44.8.24.1.1.1Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-6.16.5.0 | The Events Calendar <= 6.16.5.0 - Missing Authorization | July 6, 2026 | 6.16.5.1 | Medium |
6.15.12-6.16.2 | The Events Calendar 6.15.12-6.16.2 - Unauthenticated SQL Injection | June 8, 2026 | 6.16.3 | High |
*-6.15.17 | The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_import | March 9, 2026 | 6.15.17.1 | High |
*-6.15.16 | The Events Calendar <= 6.15.16 - Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API | February 25, 2026 | 6.15.16.1 | Medium |
*-6.15.13 | The Events Calendar <= 6.15.13 - Missing Authorization to Authenticated (Subscriber+) Data Migration Control | January 20, 2026 | 6.15.13.1 | Medium |
*-6.15.12.2 | The Events Calendar <= 6.15.12.2 - Missing Authorization | January 9, 2026 | 6.15.13 | Medium |
*-6.15.9 | The Events Calendar <= 6.15.9 - Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information Exposure | November 4, 2025 | 6.15.10 | Medium |
6.15.1.1-6.15.9 | The Events Calendar 6.15.1.1 - 6.15.9 - Unauthenticated SQL Injection via s | November 4, 2025 | 6.15.10 | High |
*-6.15.9 | The Events Calendar <= 6.15.9 - Missing Authorization to Authenticated (Subscriber+) Draft Event Title/QR Code Exposure | October 30, 2025 | 6.15.10 | Medium |
*-6.15.2 | The Events Calendar <= 6.15.2 - Missing Authorization to Unauthenticated Password-Protected Information Disclosure | September 15, 2025 | 6.15.3 | Medium |
*-6.15.1 | The Events Calendar <= 6.15.1 - Unauthenticated SQL Injection | September 11, 2025 | 6.15.1.1 | High |
*-6.13.2 | The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting | June 10, 2025 | 6.13.2.1 | Medium |
*-6.11.2.1 | The Events Calendar <= 6.11.2.1 - Missing Authorization | May 19, 2025 | 6.12.0 | Medium |
*-6.9.0 | The Events Calendar <= 6.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | January 22, 2025 | 6.9.1 | Medium |
*-6.7.0 | The Events Calendar <= 6.7.0 - Cross-Site Request Forgery | January 9, 2025 | 6.7.1 | Medium |
*-6.8.2 | The Events Calendar <= 6.8.2 - Missing Authorization to Unauthenticated Password Protected Event Disclosure | November 25, 2024 | 6.8.2.1 | Medium |
*-6.6.4 | The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection | September 24, 2024 | 6.6.4.1 | Critical |
*-6.6.3 | The Events Calendar <= 6.6.3 - Authenticated (Administrator+) Stored Cross-Site Scripting | July 31, 2024 | 6.6.4 | Medium |
*-6.6.3 | The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site Scripting | July 23, 2024 | 6.6.4 | High |
*-6.5.1.4 | The Events Calendar <= 6.5.1.4 - Cross-Site Request Forgery via action_restore_events | July 5, 2024 | 6.5.1.5 | Medium |
*-6.4.0 | The Events Calendar Free & Pro <= 6.4.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Events Access | May 24, 2024 | 6.4.0.1 | Medium |
*-6.4.0 | The Events Calendar <= 6.4.0 - Reflected Cross-Site Scripting | May 14, 2024 | 6.4.0.1 | Medium |
*-6.3.0 | The Events Calendar <= 6.3.0 - Cross-Site Request Forgery to Notice Dismissal | April 10, 2024 | 6.3.1 | Medium |
*-6.2.8.2 | The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposure | January 12, 2024 | 6.2.9 | Medium |
[*, 6.2.8.1) | The Events Calendar <= 6.2.8 - Information Disclosure | November 20, 2023 | 6.2.8.1 | Medium |
Selected source records
Published: July 6, 2026
Published: June 8, 2026
Published: March 9, 2026
Published: February 25, 2026
Published: January 20, 2026
Published: January 9, 2026
Published: November 4, 2025
Published: November 4, 2025
Published: September 24, 2024
Published: September 11, 2025
Published: March 9, 2026
Published: November 4, 2025
Published: June 8, 2026
Published: July 23, 2024
Published: June 10, 2025
Published: January 22, 2025
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.