WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Community Events

The purpose of this plugin is to allow users to create a schedule of upcoming events and display events for the next 7 days in an AJAX-driven box or d …

12Reported vulnerabilities
9.8Highest CVSS score
1.5.9Latest version
30+Active installs

What to do now

Update Community Events to 1.5.9 or later. 12 of these have a fixed version available. Updating resolves them.

Plugin last updated: February 15, 2026 / Tested up to WordPress: 6.9.7 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2015-3313 Critical 9.8 8.3% 1.3.5 and earlier 1.4 September 7, 2017
CVE-2021-24496 Medium 6.1 0.8% Before 1.4.8 1.4.8 August 2, 2021
CVE-2025-10586 Critical 9.8 0.5% 0 to 1.5.1 (inclusive) 1.5.2 October 9, 2025
CVE-2025-10587 Critical 9.8 0.4% 0 to 1.5.1 (inclusive) 1.5.2 October 8, 2025
CVE-2024-6271 Medium 5.4 0.3% Before 1.5 1.5 July 22, 2024
CVE-2024-6270 Medium 4.8 0.4% Before 1.5.1 1.5.1 August 5, 2024
CVE-2025-12646 High 7.5 0.3% 0 to 1.5.4 (inclusive) 1.5.5 November 19, 2025
CVE-2025-11995 High 7.2 0.3% 0 to 1.5.2 (inclusive) 1.5.3 November 1, 2025
CVE-2022-44742 Medium 5.5 0.4% 1.4.8 and earlier 1.4.9 November 25, 2022
CVE-2025-14029 Medium 5.3 0.2% 0 to 1.5.6 (inclusive) 1.5.7 January 17, 2026
CVE-2026-2429 Medium 4.9 0.3% 0 to 1.5.8 (inclusive) 1.5.9 March 7, 2026
CVE-2026-1649 Medium 4.4 0.2% 0 to 1.5.7 (inclusive) 1.5.8 February 18, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.