CVE-2024-4180: Stellarwp The Events Calendar
Critical severity, CVSS 9.1. EPSS: 2.1% chance of exploitation in the next 30 days.
The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.
Affected products
- Stellarwp The Events Calendar: before 6.4.0.1 (fixed in 6.4.0.1)
Published 2024-06-04. Last modified 2026-06-17.