Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

The Events Calendar Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 30 vulnerability records associated with The Events Calendar, published between 2016 and 2026.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

At a glance

Security Snapshot

30Total records
1Critical
5High
23Medium
0Low
1Informational
30Patched records
0Currently marked unpatched
2016-04-25First disclosure
2026-07-06Latest disclosure
29 of 30CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
201611 records
201911 records
202211 records
202333 records
202499 records
202599 records
202666 records

Severity Breakdown

SeverityRecordsShare
Critical13.3%
High516.7%
Medium2376.7%
Informational13.3%

Vulnerability-Type Breakdown

Missing Authorization

11 records36.7%

First: 2022. Latest: 2026.

Cross-Site Scripting

7 records23.3%

First: 2019. Latest: 2025.

SQL Injection

4 records13.3%

First: 2024. Latest: 2026.

Information Disclosure

3 records10%

First: 2023. Latest: 2025.

CSRF

3 records10%

First: 2024. Latest: 2025.

Other

1 record3.3%

First: 2016. Latest: 2016.

Path Traversal

1 record3.3%

First: 2026. Latest: 2026.

Patch Status

Patched
30
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 6.16.5.1
  • 6.16.3
  • 6.15.17.1
  • 6.15.16.1
  • 6.15.13.1
  • 6.15.13
  • 6.15.10
  • 6.15.3
  • 6.15.1.1
  • 6.13.2.1
  • 6.12.0
  • 6.9.1
  • 6.7.1
  • 6.8.2.1
  • 6.6.4.1
  • 6.6.4
  • 6.5.1.5
  • 6.4.0.1
  • 6.3.1
  • 6.2.9
  • 6.2.8.1
  • 6.1.3
  • 5.16.4.1
  • 5.14.0.4
  • 4.8.2
  • 4.1.1.1

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-6.16.5.0The Events Calendar <= 6.16.5.0 - Missing AuthorizationJuly 6, 20266.16.5.1Medium
6.15.12-6.16.2The Events Calendar 6.15.12-6.16.2 - Unauthenticated SQL InjectionJune 8, 20266.16.3High
*-6.15.17The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_importMarch 9, 20266.15.17.1High
*-6.15.16The Events Calendar <= 6.15.16 - Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST APIFebruary 25, 20266.15.16.1Medium
*-6.15.13The Events Calendar <= 6.15.13 - Missing Authorization to Authenticated (Subscriber+) Data Migration ControlJanuary 20, 20266.15.13.1Medium
*-6.15.12.2The Events Calendar <= 6.15.12.2 - Missing AuthorizationJanuary 9, 20266.15.13Medium
*-6.15.9The Events Calendar <= 6.15.9 - Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information ExposureNovember 4, 20256.15.10Medium
6.15.1.1-6.15.9The Events Calendar 6.15.1.1 - 6.15.9 - Unauthenticated SQL Injection via sNovember 4, 20256.15.10High
*-6.15.9The Events Calendar <= 6.15.9 - Missing Authorization to Authenticated (Subscriber+) Draft Event Title/QR Code ExposureOctober 30, 20256.15.10Medium
*-6.15.2The Events Calendar <= 6.15.2 - Missing Authorization to Unauthenticated Password-Protected Information DisclosureSeptember 15, 20256.15.3Medium
*-6.15.1The Events Calendar <= 6.15.1 - Unauthenticated SQL InjectionSeptember 11, 20256.15.1.1High
*-6.13.2The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site ScriptingJune 10, 20256.13.2.1Medium
*-6.11.2.1The Events Calendar <= 6.11.2.1 - Missing AuthorizationMay 19, 20256.12.0Medium
*-6.9.0The Events Calendar <= 6.9.0 - Authenticated (Contributor+) Stored Cross-Site ScriptingJanuary 22, 20256.9.1Medium
*-6.7.0The Events Calendar <= 6.7.0 - Cross-Site Request ForgeryJanuary 9, 20256.7.1Medium
*-6.8.2The Events Calendar <= 6.8.2 - Missing Authorization to Unauthenticated Password Protected Event DisclosureNovember 25, 20246.8.2.1Medium
*-6.6.4The Events Calendar <= 6.6.4 - Unauthenticated SQL InjectionSeptember 24, 20246.6.4.1Critical
*-6.6.3The Events Calendar <= 6.6.3 - Authenticated (Administrator+) Stored Cross-Site ScriptingJuly 31, 20246.6.4Medium
*-6.6.3The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site ScriptingJuly 23, 20246.6.4High
*-6.5.1.4The Events Calendar <= 6.5.1.4 - Cross-Site Request Forgery via action_restore_eventsJuly 5, 20246.5.1.5Medium
*-6.4.0The Events Calendar Free & Pro <= 6.4.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Events AccessMay 24, 20246.4.0.1Medium
*-6.4.0The Events Calendar <= 6.4.0 - Reflected Cross-Site ScriptingMay 14, 20246.4.0.1Medium
*-6.3.0The Events Calendar <= 6.3.0 - Cross-Site Request Forgery to Notice DismissalApril 10, 20246.3.1Medium
*-6.2.8.2The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information ExposureJanuary 12, 20246.2.9Medium
[*, 6.2.8.1)The Events Calendar <= 6.2.8 - Information DisclosureNovember 20, 20236.2.8.1Medium

Selected source records

Latest Records

MediumCVE-2026-13390

The Events Calendar <= 6.16.5.0 - Missing Authorization

Published: July 6, 2026

Affected versions
*-6.16.5.0
Patched versions
6.16.5.1
Original Wordfence record
HighCVE-2026-49772

The Events Calendar 6.15.12-6.16.2 - Unauthenticated SQL Injection

Published: June 8, 2026

Affected versions
6.15.12-6.16.2
Patched versions
6.16.3
Original Wordfence record
HighCVE-2026-3585

The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_import

Published: March 9, 2026

Affected versions
*-6.15.17
Patched versions
6.15.17.1
Original Wordfence record
MediumCVE-2026-2694

The Events Calendar <= 6.15.16 - Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API

Published: February 25, 2026

Affected versions
*-6.15.16
Patched versions
6.15.16.1
Original Wordfence record
MediumCVE-2025-15043

The Events Calendar <= 6.15.13 - Missing Authorization to Authenticated (Subscriber+) Data Migration Control

Published: January 20, 2026

Affected versions
*-6.15.13
Patched versions
6.15.13.1
Original Wordfence record
MediumCVE-2025-69352

The Events Calendar <= 6.15.12.2 - Missing Authorization

Published: January 9, 2026

Affected versions
*-6.15.12.2
Patched versions
6.15.13
Original Wordfence record
MediumCVE-2025-12192

The Events Calendar <= 6.15.9 - Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information Exposure

Published: November 4, 2025

Affected versions
*-6.15.9
Patched versions
6.15.10
Original Wordfence record
HighCVE-2025-12197

The Events Calendar 6.15.1.1 - 6.15.9 - Unauthenticated SQL Injection via s

Published: November 4, 2025

Affected versions
6.15.1.1-6.15.9
Patched versions
6.15.10
Original Wordfence record

Highest-Severity Records

CriticalCVE-2024-8275

The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection

Published: September 24, 2024

Affected versions
*-6.6.4
Patched versions
6.6.4.1
Original Wordfence record
HighCVE-2025-9807

The Events Calendar <= 6.15.1 - Unauthenticated SQL Injection

Published: September 11, 2025

Affected versions
*-6.15.1
Patched versions
6.15.1.1
Original Wordfence record
HighCVE-2026-3585

The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_import

Published: March 9, 2026

Affected versions
*-6.15.17
Patched versions
6.15.17.1
Original Wordfence record
HighCVE-2025-12197

The Events Calendar 6.15.1.1 - 6.15.9 - Unauthenticated SQL Injection via s

Published: November 4, 2025

Affected versions
6.15.1.1-6.15.9
Patched versions
6.15.10
Original Wordfence record
HighCVE-2026-49772

The Events Calendar 6.15.12-6.16.2 - Unauthenticated SQL Injection

Published: June 8, 2026

Affected versions
6.15.12-6.16.2
Patched versions
6.16.3
Original Wordfence record
HighCVE-2024-6931

The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site Scripting

Published: July 23, 2024

Affected versions
*-6.6.3
Patched versions
6.6.4
Original Wordfence record
MediumCVE-2025-5144

The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

Published: June 10, 2025

Affected versions
*-6.13.2
Patched versions
6.13.2.1
Original Wordfence record
MediumCVE-2024-12118

The Events Calendar <= 6.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Published: January 22, 2025

Affected versions
*-6.9.0
Patched versions
6.9.1
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory