Executive brief
A critical security flaw has been identified in The Events Calendar, a popular WordPress plugin used to manage and display event schedules. This vulnerability allows an unauthorized attacker to interact directly with the website's database without needing a password. Successful exploitation could lead to the theft of sensitive customer information or disruption of the website's operations.
Technical details
The Events Calendar plugin for WordPress is vulnerable to a blind SQL injection due to improper neutralization of special elements in SQL commands. The flaw exists in versions 6.15.12 through 6.16.2. An unauthenticated remote attacker can exploit this by sending specially crafted network requests to the affected component, allowing them to extract sensitive data from the database or cause service degradation. The vulnerability has been addressed in version 6.16.3.
Affected products
- StellarWP / Liquid Web The Events Calendar 6.15.12 through 6.16.2
Timeline
- 2026-05-24: other: Reported by researcher vtim
- 2026-06-08: advisory: Patchstack advisory published
- 2026-06-16: disclosed: CVE published to NVD