Tri's vulnerability profile centers on a small portfolio of WordPress plugins focused on event management and page building, including GigPress, Event Tickets, Panel Builder, and The Events Calendar. The recurring exposure reflects common application-layer input-handling weaknesses—cross-site scripting, SQL injection, open redirects, and related neutralization gaps—that are characteristic of web-facing plugins with user-supplied content and database interaction, and the vendor's disclosures have an elevated tendency toward public exploit availability. Defenders tracking WordPress environments should monitor this vendor's advisories and prioritize patching in internet-reachable event management deployments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tri over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25028MEDIUM The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary re | Jan 24, 2022 | 6.1 | 32 | NO | YES |
CVE-2015-4066MEDIUM Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow remote authenticated users to execute arbitrary SQL commands vi | May 27, 2015 | 6.5 | 27 | NO | YES |
CVE-2023-0381HIGH The GigPress WordPress plugin through 2.3.28 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated | Feb 27, 2023 | 8.8 | 26 | NO | NO |
CVE-2020-36626MEDIUM A vulnerability classified as critical has been found in Modern Tribe Panel Builder Plugin. Affected is the function add_post_content_filtered_to_search_sql of the file ModularCont | Dec 27, 2022 | 6.1 | 22 | NO | NO |
CVE-2015-9353HIGH The gigpress plugin before 2.3.11 for WordPress has SQL injection in the admin area, a different vulnerability than CVE-2015-4066. | Aug 28, 2019 | 7.2 | 19 | NO | NO |
CVE-2024-1295MEDIUM The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking | Jun 14, 2024 | 6.5 | 18 | NO | NO |
CVE-2023-7233MEDIUM The GigPress WordPress plugin through 2.3.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Sc | Feb 12, 2024 | 4.8 | 16 | NO | NO |
CVE-2022-4759MEDIUM The GigPress WordPress plugin before 2.3.28 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, w | Feb 13, 2023 | 5.4 | 16 | NO | NO |
CVE-2015-9354MEDIUM The gigpress plugin before 2.3.11 for WordPress has XSS. | Aug 28, 2019 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tri.
Media articles that mention a CVE ID that affects a product developed by Tri — matched by CVE ID, not by vendor name.