Extension WordPress
Vulnérabilités The Events Calendar, page 2
Cette page rassemble les failles publiées pour The Events Calendar, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de The Events Calendar
29 fiches
The Events Calendar <= 6.4.0 – Reflected Cross-Site Scripting
The The Events Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view_data' parameter in all versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for…
*-6.4.0
6.4.0.1
14/05/2024
The Events Calendar <= 6.3.0 – Cross-Site Request Forgery to Notice Dismissal
The The Events Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.3.0. This is due to missing or incorrect nonce validation on the maybe_dismiss() function. This makes it possible for…
*-6.3.0
6.3.1
10/04/2024
The Events Calendar <= 6.2.8.2 – Unauthenticated Sensitive Information Exposure
The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it possible for unauthenticated attackers to extract potentially…
*-6.2.8.2
6.2.9
12/01/2024
The Events Calendar <= 6.2.8 – Information Disclosure
The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.2.8 via the get_data function. This makes it possible for unauthenticated attackers to extract sensitive data including private…
[*, 6.2.8.1)
6.2.8.1
20/11/2023
The Events Calendar <= 6.1.2.2 – Missing Authorization
The The Events Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_ical_output_for_an_event() function in versions up to, and including, 6.1.2.2. This makes it possible for unauthenticated attackers…
*-6.1.2.2
6.1.3
25/07/2023
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
4.9.0-5.16.4
5.16.4.1
18/07/2023
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 5.14.0.4)
5.14.0.4
04/03/2022
The Events Calendar <= 4.8.1 – Cross-Site Scripting via tribe_paged Parameter
The Events Calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.
[*, 4.8.2)
4.8.2
04/03/2019
The Events Calendar < 4.1.1.1 – Open Redirect
The Events Calendar plugin for WordPress is vulnerable to an open redirect vulnerability in versions before 4.1.1.1. This allows attackers to redirect victims to an untrusted site via a crafted link on a vulnerable trusted site.
*-4.1.1
4.1.1.1
25/04/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.