Vulnerability record · CVE-2024-8275 · published 25 September 2024
CVE-2024-8275: The Events Calendar WordPress plugin SQL injection via order parameter
Stellarwp · The Events Calendar
The Events Calendar plugin for WordPress is vulnerable to SQL injection through the 'order' parameter of the tribe_has_next_event() function in versions up to and including 6.6.4. The flaw stems from insufficient escaping of user input and inadequate query preparation, allowing unauthenticated attackers to inject SQL. It matters because successful exploitation can expose sensitive database contents, though only sites that have manually added tribe_has_next_event() are affected.
Description
The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Only sites that have manually added tribe_has_next_event() will be vulnerable to this SQL injection.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS score is critical (9.8) and EPSS is high, but exploitation is limited to sites that manually added the vulnerable function, reducing overall risk.
What it is
The Events Calendar plugin for WordPress is vulnerable to SQL injection through the 'order' parameter of the tribe_has_next_event() function in versions up to and including 6.6.4. The flaw stems from insufficient escaping of user input and inadequate query preparation, allowing unauthenticated attackers to inject SQL. It matters because successful exploitation can expose sensitive database contents, though only sites that have manually added tribe_has_next_event() are affected.
Impact
An attacker can append arbitrary SQL queries to existing queries, enabling extraction of sensitive information from the WordPress database. This could include user credentials, configuration data, or other stored secrets.
Attack surface
The vulnerability is reachable over the network via the 'order' parameter without authentication or user interaction, as reflected in the CVSS vector AV:N/AC:L/PR:N/UI:N. However, exploitation requires the site to have manually added the tribe_has_next_event() function, limiting the attack surface to a subset of installations.
Exploitation
The vulnerability is not listed in CISA KEV, but EPSS indicates a high probability of exploitation (0.49914, 98.8th percentile). A patch reference is available, and no ransomware groups are documented as using it.
What to do
- Update The Events Calendar plugin to a version later than 6.6.4 as soon as possible.
- If the tribe_has_next_event() function was manually added, remove or disable it until patched.
- Apply input validation and parameterized queries if custom code calls tribe_has_next_event().
- Monitor for and restrict unnecessary database query exposure from custom template functions.
- Review WordPress database activity for anomalous SQL patterns.
Detection
- Inspect web server logs for requests containing suspicious 'order' parameter values, such as SQL keywords or comment sequences.
- Enable and review database query logging for unexpected UNION, SELECT, or stacked queries originating from WordPress.
- Use a web application firewall (WAF) to alert on SQL injection patterns targeting the 'order' parameter.
- Audit custom theme or plugin code for calls to tribe_has_next_event() and ensure they are removed or secured.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-8275 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-8275), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.