CVE-2024-4180: Stellarwp The Events Calendar

Critical severity, CVSS 9.1. EPSS: 2.1% chance of exploitation in the next 30 days.

The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.

Affected products

  • Stellarwp The Events Calendar: before 6.4.0.1 (fixed in 6.4.0.1)

Published 2024-06-04. Last modified 2026-06-17.