Known vulnerabilities in Event Post
The only WordPress plugin using native posts as full calendar events with begin and end date, geolocation, color and weather.
12Reported vulnerabilities
9.8Highest CVSS score
6.1.1Latest version
1,000+Active installs
What to do now
Update Event Post to 6.1.1 or later.
11 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2024-38735 | Critical | 0.5% | 5.9.5 and earlier | 5.9.6 |
July 11, 2024 |
| CVE-2025-26923 | Medium | 0.3% | 5.9.8 and earlier | 5.9.9 |
March 11, 2025 |
| CVE-2025-24585 | Medium | 0.4% | 5.9.7 and earlier | 5.9.8 |
January 24, 2025 |
| CVE-2023-49179 | Medium | 0.4% | 5.9.0 and earlier | 5.9.1 |
November 29, 2023 |
| CVE-2025-62042 | Medium | 0.2% | 5.10.3 and earlier | 5.10.4 |
October 16, 2025 |
| CVE-2025-49298 | Medium | 0.2% | 5.10.1 and earlier | 5.10.2 |
June 5, 2025 |
| CVE-2025-46228 | Medium | 0.2% | 5.9.11 and earlier | 5.10.0 |
April 22, 2025 |
| CVE-2024-10186 | Medium | 0.3% | Before 5.9.7 | 5.9.7 |
November 6, 2024 |
| CVE-2026-65486 | Medium | 0.3% | 6.1.0 and earlier | 6.1.1 |
July 22, 2026 |
| CVE-2025-2167 | Medium | 0.2% | 5.9.9 and earlier | 5.9.10 |
March 25, 2025 |
| CVE-2024-1375 | Medium | 0.2% | 0 to 5.9.10 (inclusive) | — | July 12, 2024 |
| CVE-2024-1376 | Medium | 0.3% | Before 5.9.5 | 5.9.5 |
May 24, 2024 |