Community Events

Information

Software Type Plugin
Software Slug community-events (view on wordpress.org)
Software Status Active
Software Author jackdewey
Software Website ylefebvre.github.io
Software Downloads 19,291
Software Active Installs 30
Software Record Last Updated July 21, 2026

12 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
Community Events <= 1.5.8 - Authenticated (Administrator+) SQL Injection via 'ce_venue_name' CSV Field Patched CVE-2026-2429 4.9 Bee March 6, 2026
Community Events <= 1.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'ce_venue_name' Parameter Patched CVE-2026-1649 4.4 Bee February 17, 2026
Community Events <= 1.5.6 - Missing Authorization to Unauthenticated Arbitrary Event Approval via 'eventlist' Parameter Patched CVE-2025-14029 5.3 Itthidej Aramsri (Boeing777) January 16, 2026
Community Events <= 1.5.4 - Unauthenticated SQL Injection Patched CVE-2025-12646 7.5 Muhammad Yudha - DJ November 18, 2025
Community Events <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting Patched CVE-2025-11995 7.2 ifoundbug October 31, 2025
Community Events <= 1.5.1 - Unauthenticated SQL Injection Patched CVE-2025-10586 9.8 ifoundbug October 8, 2025
Community Events <= 1.5.1 - Unauthenticated SQL Injection Patched CVE-2025-10587 9.8 ifoundbug October 7, 2025
Community Events <= 1.5 - Authenticated (Admin+) Stored Cross-Site Scripting Patched CVE-2024-6270 4.4 Bob Matyas July 15, 2024
Community Events <= 1.4.9 - Cross-Site Request Forgery Patched CVE-2024-6271 4.3 Bob Matyas July 1, 2024
Community Events <= 1.4.8 - Authenticated (Administrator+) Stored Cross Site Scripting Patched CVE-2022-44742 5.5 sk4rl1ghT November 25, 2022
Community Events <= 1.4.7 - Reflected Cross-Site Scripting Patched CVE-2021-24496 6.1 iohex July 2, 2021
Community Events < 1.4 - SQL Injection Patched CVE-2015-3313 9.8 Hannes Trunde April 20, 2015

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation