cleantalk
Vulnerabilities and Security Researches

The Events Calendar, CVE-2026-49772

CVE, Research URL

CVE-2026-49772

Application

The Events Calendar

Published on
Jun 16, 2026
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6.15.12 through 6.16.2.
Affected versions
max 6.16.3.
Status
vulnerable