CVE · Medium

CVE-2025-24537 — The Events Calendar [the-events-calendar] < 6.7.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-24537 The Events Calendar [the-events-calendar] < 6.7.1 Cross-Site Request Forgery (CSRF) Medium 5.4 < 6.7.1 6.7.1 2025-01-09

CVE-2025-24537

The Events Calendar plugin for WordPress contains a security flaw in versions up to 6.7.0, which allows unauthorized individuals to manipulate the system by exploiting a missing validation check within an unspecified function. This can be achieved through social engineering tactics, where an attacker convinces an administrator to click on a malicious link, thereby executing unintended actions. The consequences of this vulnerability are currently unclear.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.