Junglewise Threat Intelligence

CVE-2025-69135: CurlyThemes Events Schedule SQL injection in WordPress plugin

CVE-2025-69135 · Severity: high · CVSS 8.5 · Published 2026-06-17

Executive brief

The Events Schedule plugin for WordPress, used to manage and display event calendars, contains a security vulnerability that allows users with basic 'Subscriber' accounts to execute unauthorized database commands. An attacker could exploit this to steal sensitive information from the website's database, such as user credentials or private site data. This poses a significant risk to data confidentiality and the overall integrity of the affected website.

Technical details

A SQL injection vulnerability exists in the CurlyThemes Events Schedule - WordPress Events Calendar Plugin (versions <= 2.7.2) due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is accessible to authenticated users with 'Subscriber' privileges, allowing them to perform unauthorized database queries via the network without user interaction. This can lead to full data exfiltration from the WordPress database. As of the advisory date, no official patch has been released by the vendor, though third-party mitigation rules are available.

Affected products

  • CurlyThemes Events Schedule - WordPress Events Calendar Plugin <= 2.7.2

Timeline

  • 2025-10-22: other: Vulnerability reported by researcher 0xd4rk5id3
  • 2026-05-26: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: NVD publication date

References