← Vulnerability feed

Vulnerability record · CVE-2024-8275 · published 25 September 2024

CVE-2024-8275: The Events Calendar WordPress plugin SQL injection via order parameter

Stellarwp · The Events Calendar

The Events Calendar plugin for WordPress is vulnerable to SQL injection through the 'order' parameter of the tribe_has_next_event() function in versions up to and including 6.6.4. The flaw stems from insufficient escaping of user input and inadequate query preparation, allowing unauthenticated attackers to inject SQL. It matters because successful exploitation can expose sensitive database contents, though only sites that have manually added tribe_has_next_event() are affected.

9.8 CVSS 3.1 Critical EPSS 50% · top 1.1% CWE-89 · SQL injection
9.8CVSS 3.1 base score
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Only sites that have manually added tribe_has_next_event() will be vulnerable to this SQL injection.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityCVSS score is critical (9.8) and EPSS is high, but exploitation is limited to sites that manually added the vulnerable function, reducing overall risk.

What it is

The Events Calendar plugin for WordPress is vulnerable to SQL injection through the 'order' parameter of the tribe_has_next_event() function in versions up to and including 6.6.4. The flaw stems from insufficient escaping of user input and inadequate query preparation, allowing unauthenticated attackers to inject SQL. It matters because successful exploitation can expose sensitive database contents, though only sites that have manually added tribe_has_next_event() are affected.

Impact

An attacker can append arbitrary SQL queries to existing queries, enabling extraction of sensitive information from the WordPress database. This could include user credentials, configuration data, or other stored secrets.

Attack surface

The vulnerability is reachable over the network via the 'order' parameter without authentication or user interaction, as reflected in the CVSS vector AV:N/AC:L/PR:N/UI:N. However, exploitation requires the site to have manually added the tribe_has_next_event() function, limiting the attack surface to a subset of installations.

Exploitation

The vulnerability is not listed in CISA KEV, but EPSS indicates a high probability of exploitation (0.49914, 98.8th percentile). A patch reference is available, and no ransomware groups are documented as using it.

What to do

  • Update The Events Calendar plugin to a version later than 6.6.4 as soon as possible.
  • If the tribe_has_next_event() function was manually added, remove or disable it until patched.
  • Apply input validation and parameterized queries if custom code calls tribe_has_next_event().
  • Monitor for and restrict unnecessary database query exposure from custom template functions.
  • Review WordPress database activity for anomalous SQL patterns.

Detection

  • Inspect web server logs for requests containing suspicious 'order' parameter values, such as SQL keywords or comment sequences.
  • Enable and review database query logging for unexpected UNION, SELECT, or stacked queries originating from WordPress.
  • Use a web application firewall (WAF) to alert on SQL injection patterns targeting the 'order' parameter.
  • Audit custom theme or plugin code for calls to tribe_has_next_event() and ensure they are removed or secured.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-8275 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2024-4180Stellarwp the events calendar cross-site scripting vulnerabilityThe Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.EPSS 1.8%7.5CVE-2023-6203Stellarwp the events calendar vulnerabilityThe Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted requestEPSS 0.78%6.1CVE-2024-6931Stellarwp the events calendar cross-site scripting vulnerabilityThe The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6…EPSS 17%6.1CVE-2019-15109Stellarwp the events calendar cross-site scripting vulnerabilityThe the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.EPSS 1.1%5.4CVE-2025-5144Stellarwp the events calendar cross-site scripting vulnerabilityThe The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and…EPSS 0.26%5.3CVE-2024-5333Stellarwp the events calendar vulnerabilityThe Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access informatio…EPSS 1.1%5.3CVE-2023-6557Stellarwp the events calendar missing authorization vulnerabilityThe The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the ro…EPSS 0.56%4.8CVE-2024-8493Stellarwp the events calendar cross-site scripting vulnerabilityThe Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as a…EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2024-8275), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.