Stellarwp develops WordPress plugins focused on events and media functionality, a narrowly scoped but prominently used addition to WordPress installations. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, concentrating in flagship products such as The Events Calendar and Image Widget through recurring web-application weakness classes including cross-site scripting, SQL injection, and missing authorization controls. Defenders managing WordPress environments should prioritize updates for these plugins and treat them as potential entry points for code execution and privilege escalation; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stellarwp over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8275CRITICAL The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6 | Sep 25, 2024 | 9.8 | 58 | NO | NO |
CVE-2024-4180CRITICAL The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX. | Jun 4, 2024 | 9.1 | 39 | NO | YES |
CVE-2025-12197HIGH The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15.1.1 to 6.15.9 due to insufficient escaping on the user supp | Nov 5, 2025 | 7.5 | 34 | NO | NO |
CVE-2025-9807HIGH The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all versions up to, and including, 6.15.1 due to insufficient escapi | Sep 12, 2025 | 7.5 | 27 | NO | NO |
CVE-2024-6931MEDIUM The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6.6.3 due to insufficient input | Sep 27, 2024 | 6.1 | 27 | NO | NO |
CVE-2025-9808MEDIUM The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for un | Sep 16, 2025 | 5.3 | 26 | NO | YES |
CVE-2024-5333MEDIUM The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected even | Dec 16, 2024 | 5.3 | 26 | NO | YES |
CVE-2026-3585HIGH The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.17 via the 'ajax_create_import' function. This makes it poss | Mar 10, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-42643MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP Image Widget image-widget allows Stored XSS.This issue affects Image | Apr 29, 2026 | 5.9 | 24 | NO | NO |
CVE-2023-6203HIGH The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request | Dec 18, 2023 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stellarwp.
Media articles that mention a CVE ID that affects a product developed by Stellarwp — matched by CVE ID, not by vendor name.