WP Clinic
Log in Sign up

CVE · Medium

CVE-2025-48246 — The Events Calendar [the-events-calendar] < 6.12.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-48246 The Events Calendar [the-events-calendar] < 6.12.0 Missing Authorization Medium 5.4 < 6.12.0 6.12.0 2025-05-19

CVE-2025-48246

The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax_preview_import() function in versions up to, and including, 6.11.2.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to create an import.

Source: Wordfence

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.