PLUGIN SECURITY

Is The Events Calendar safe?

The Events Calendar: #1 calendar plugin for WordPress. Create/manage events (virtual too!) on your site with the free plugin.

What this plugin does

  • Slug: the-events-calendar
  • Author: Nexcess
  • 600000+ active installs
  • 84/100 rating (2450 reviews on wordpress.org)
  • 85674350 all-time downloads
  • On WordPress.org since 2010-01-19

calendarEventeventsorganizerschedule

Maintenance status

  • Latest known version: 6.17.2
  • Last updated: 2026-08-20 12:18pm GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+

Known vulnerabilities

29 known CVEs on file for The Events Calendar.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-78265 The Events Calendar [the-events-calendar] < 6.17.3 Deserialization of Untrusted Data Critical 9.8 < 6.17.3 6.17.3 2026-08-24 ⚠ update needed
CVE-2026-49772 The Events Calendar [the-events-calendar] < 6.16.3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.3 < 6.16.3 6.16.3 2026-06-08 ✓ fixed in latest
CVE-2025-15043 The Events Calendar [the-events-calendar] < 6.15.13.1 Missing Authorization Medium 5.4 < 6.15.13.1 6.15.13.1 2026-01-20 ✓ fixed in latest
CVE-2025-69352 The Events Calendar [the-events-calendar] < 6.15.13 Missing Authorization Medium 5.4 < 6.15.13 6.15.13 2026-01-06 ✓ fixed in latest
CVE-2025-12192 The Events Calendar [the-events-calendar] < 6.15.10 Incorrect Comparison Medium 5.3 < 6.15.10 6.15.10 2025-11-04 ✓ fixed in latest
CVE-2025-12197 The Events Calendar [the-events-calendar] < 6.15.10 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 6.15.10 6.15.10 2025-11-04 ✓ fixed in latest
CVE-2025-12175 The Events Calendar [the-events-calendar] < 6.15.10 Missing Authorization Medium 4.3 < 6.15.10 6.15.10 2025-10-30 ✓ fixed in latest
CVE-2025-48246 The Events Calendar [the-events-calendar] < 6.12.0 Missing Authorization Medium 5.4 < 6.12.0 6.12.0 2025-05-19 ✓ fixed in latest
+ 48 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-12118 The Events Calendar [the-events-calendar] < 6.9.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 6.9.1 6.9.1 2025-01-22 ✓ fixed in latest
CVE-2025-24537 The Events Calendar [the-events-calendar] < 6.7.1 Cross-Site Request Forgery (CSRF) Medium 5.4 < 6.7.1 6.7.1 2025-01-09 ✓ fixed in latest
CVE-2024-5333 The Events Calendar [the-events-calendar] < 6.8.2.1 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 6.8.2.1 6.8.2.1 2024-11-25 ✓ fixed in latest
CVE-2024-8275 The Events Calendar [the-events-calendar] < 6.6.4.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 6.6.4.1 6.6.4.1 2024-09-24 ✓ fixed in latest
CVE-2024-6931 The Events Calendar [the-events-calendar] < 6.6.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 6.6.4 6.6.4 2024-07-23 ✓ fixed in latest
CVE-2024-37518 The Events Calendar [the-events-calendar] < 6.5.1.5 Cross-Site Request Forgery (CSRF) Medium 4.3 < 6.5.1.5 6.5.1.5 2024-07-05 ✓ fixed in latest
CVE-2024-1295 The Events Calendar [the-events-calendar] < 6.4.0.1 Improper Access Control Medium 6.5 < 6.4.0.1 6.4.0.1 2024-05-24 ✓ fixed in latest
CVE-2024-4180 The Events Calendar [the-events-calendar] < 6.4.0.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Critical 9.1 < 6.4.0.1 6.4.0.1 2024-05-14 ✓ fixed in latest
CVE-2024-31433 The Events Calendar [the-events-calendar] < 6.3.1 Cross-Site Request Forgery (CSRF) Medium 4.3 < 6.3.1 6.3.1 2024-04-10 ✓ fixed in latest
CVE-2023-6557 The Events Calendar [the-events-calendar] < 6.2.9 Missing Authorization Medium 5.3 < 6.2.9 6.2.9 2024-01-12 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 6.2.8.1 Unknown < 6.2.8.1 6.2.8.1 2023-11-22 ✓ fixed in latest
CVE-2023-6203 The Events Calendar [the-events-calendar] < 6.2.8.1 Improper Authentication High 7.5 < 6.2.8.1 6.2.8.1 2023-11-20 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 3.0.1 Unknown < 3.0.1 3.0.1 2023-08-01 ✓ fixed in latest
CVE-2023-35777 The Events Calendar [the-events-calendar] < 6.1.3 Missing Authorization Medium 5.3 < 6.1.3 6.1.3 2023-07-25 ✓ fixed in latest
CVE-2023-33999 The Events Calendar [the-events-calendar] < 6.1.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 6.1.0 6.1.0 2023-07-18 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 4.1.1.1 Unknown < 4.1.1.1 4.1.1.1 2023-04-25 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 5.14.0.4 Unknown < 5.14.0.4 5.14.0.4 2023-02-28 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 5.14.0.4 Unknown < 5.14.0.4 5.14.0.4 2023-02-28 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 5.14.0.4 Missing Authorization Medium 6.3 < 5.14.0.4 5.14.0.4 2022-03-04 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 5.14.0.4 Unknown < 5.14.0.4 5.14.0.4 2022-02-28 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 5.14.0.4 Unknown < 5.14.0.4 5.14.0.4 2022-02-28 ✓ fixed in latest
CVE-2019-15109 The Events Calendar [the-events-calendar] < 4.8.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 4.8.2 4.8.2 2019-03-04 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 4.1.1.1 Unknown < 4.1.1.1 4.1.1.1 2016-04-25 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 4.1.1.1 Unknown < 4.1.1.1 4.1.1.1 2016-04-25 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 3.0.1 Unknown < 3.0.1 3.0.1 2014-08-01 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 6.6.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 6.6.4 6.6.4 0000-00-00 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 6.13.2.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 6.13.2.1 6.13.2.1 0000-00-00 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 6.15.17.1 Unknown < 6.15.17.1 6.15.17.1 0000-00-00 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 6.15.16.1 Unknown < 6.15.16.1 6.15.16.1 0000-00-00 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 6.15.1.1 High 7.5 < 6.15.1.1 6.15.1.1 0000-00-00 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 6.15.3 Medium 5.3 < 6.15.3 6.15.3 0000-00-00 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 6.16.5.1 Unknown < 6.16.5.1 6.16.5.1 0000-00-00 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 5.14.0.4 Unknown < 5.14.0.4 5.14.0.4 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 4.1.1.1 Unknown < 4.1.1.1 4.1.1.1 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 3.0.1 Unknown < 3.0.1 3.0.1 ✓ fixed in latest
The Events Calendar [the-events-calendar] < 5.14.0 Unknown < 5.14.0 5.14.0 ✓ fixed in latest
The Events Calendar <= 3.0 - Reflected Cross-Site Scripting (XSS) Unknown < 3.0.1 3.0.1 ✓ fixed in latest
The Events Calendar <= 4.1.1 - Open Redirect Unknown < 4.1.1.1 4.1.1.1 ✓ fixed in latest
Unauthorised AJAX Calls via Freemius Unknown < 5.14.0.4 5.14.0.4 ✓ fixed in latest
The Events Calendar < 5.14.0 - Reflected Cross-Site Scripting Unknown < 5.14.0 5.14.0 ✓ fixed in latest
CVE-2023-6203 The Events Calendar < 6.2.8.1 - Unauthenticated Arbitrary Password Protected Post Read Unknown < 6.2.8.1 6.2.8.1 ✓ fixed in latest
CVE-2024-8493 The Events Calendar < 6.6.4 - Admin+ Stored XSS Unknown < 6.6.4 6.6.4 ✓ fixed in latest
CVE-2025-5144 The Events Calendar < 6.13.2.1 - Contributor+ DOM-Based Stored XSS Unknown < 6.13.2.1 6.13.2.1 ✓ fixed in latest
CVE-2025-9807 The Events Calendar < 6.15.1.1 - Unauthenticated SQL Injection Unknown < 6.15.1.1 6.15.1.1 ✓ fixed in latest
CVE-2025-9808 The Events Calendar < 6.15.3 - Unauthenticated Password-Protected Information Disclosure Unknown < 6.15.3 6.15.3 ✓ fixed in latest
CVE-2026-2694 The Events Calendar < 6.15.16.1 - Contributor+ Event/Organizer/Venue Update/Trash via REST API Unknown < 6.15.16.1 6.15.16.1 ✓ fixed in latest
CVE-2026-3585 The Events Calendar < 6.15.17.1 - Author+ Arbitrary File Read Unknown < 6.15.17.1 6.15.17.1 ✓ fixed in latest
CVE-2026-13390 The Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Status Manipulation Unknown < 6.16.5.1 6.16.5.1 ✓ fixed in latest

How to fix it

Keep The Events Calendar updated — 6.17.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.