Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown
CVE-2024-8275
Disclosure Date: September 25, 2024 (last updated October 03, 2024)
The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Only sites that have manually added tribe_has_next_event() will be vulnerable to this SQL injection.
0
Attacker Value
Unknown
CVE-2024-39638
Disclosure Date: August 29, 2024 (last updated September 14, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roundup WP Registrations for the Events Calendar allows SQL Injection.This issue affects Registrations for the Events Calendar: from n/a through 2.12.2.
0
Attacker Value
Unknown
CVE-2024-1295
Disclosure Date: June 14, 2024 (last updated August 08, 2024)
The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldn't have access to. (e.g. password-protected events, drafts, etc.)
0
Attacker Value
Unknown
CVE-2024-4180
Disclosure Date: June 04, 2024 (last updated June 04, 2024)
The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.
0
Attacker Value
Unknown
CVE-2024-31433
Disclosure Date: April 15, 2024 (last updated April 15, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in The Events Calendar.This issue affects The Events Calendar: from n/a through 6.3.0.
0
Attacker Value
Unknown
CVE-2023-6557
Disclosure Date: February 05, 2024 (last updated October 08, 2024)
The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it possible for unauthenticated attackers to extract potentially sensitive data including post titles and IDs of pending, private and draft posts.
0
Attacker Value
Unknown
CVE-2023-52142
Disclosure Date: January 08, 2024 (last updated January 13, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cool Plugins Events Shortcodes For The Events Calendar.This issue affects Events Shortcodes For The Events Calendar: from n/a through 2.3.1.
0
Attacker Value
Unknown
CVE-2023-6203
Disclosure Date: December 18, 2023 (last updated October 08, 2024)
The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request
0
Attacker Value
Unknown
CVE-2022-4950
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
0
Attacker Value
Unknown
CVE-2021-25083
Disclosure Date: January 24, 2022 (last updated October 07, 2023)
The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting
0