cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-event-aggregator wp-event-aggregator

Direction: ascending
Jun 06, 2024

WP Event Aggregator: Import Eventbrite events, Meetup events, social events and any iCal Events into WordPress # CVE-2024-31371

CVE, Research URL

CVE-2024-31371

Date
Apr 12, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Xylus Themes WP Event Aggregator.This issue affects WP Event Aggregator: from n/a through 1.7.6.
Affected versions
max 1.7.7.
Status
vulnerable
Jul 14, 2024

WP Event Aggregator: Import Eventbrite events, Meetup events, social events and any iCal Events into WordPress # CVE-2024-38703

CVE, Research URL

CVE-2024-38703

Date
Jul 20, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xylus Themes WP Event Aggregator allows Stored XSS.This issue affects WP Event Aggregator: from n/a through 1.7.9.
Affected versions
max 1.8.0.
Status
vulnerable
Feb 13, 2025

WP Event Aggregator: Import Eventbrite events, Meetup events, social events and any iCal Events into WordPress # CVE-2025-24700

CVE, Research URL

CVE-2025-24700

Date
Feb 14, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xylus Themes WP Event Aggregator allows Reflected XSS. This issue affects WP Event Aggregator: from n/a through 1.8.2.
Affected versions
max 1.8.3.
Status
vulnerable
Apr 15, 2026

WP Event Aggregator: Import Eventbrite events, Meetup events, social events and any iCal Events into WordPress # CVE-2026-1941

CVE, Research URL

CVE-2026-1941

Date
Feb 18, 2026
Research Description
The WP Event Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_events' shortcode in all versions up to, and including, 1.8.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.9.0.
Status
vulnerable