logo

CVE-2026-49772: The Events Calendar Blind SQL Injection (CVSS 9.3)

ID: aa7a5b76-0793-50a1-967f-006b40498d74

STIX ID: report--aa7a5b76-0793-50a1-967f-006b40498d74

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

...
...

**Executive Summary:** A critical (CVSS 9.3) blind SQL injection (CVE-2026-49772) was disclosed in The Events Calendar plugin (versions 6.15.12–6.16.2), allowing unauthenticated attackers to exfiltrate WordPress database contents (including admin credential hashes, user PII, and stored API keys) via boolean- or time-based SQLi techniques; immediate patching to versions after 6.16.2, deploying WAF rules, or disabling the plugin are recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.