CVE-2026-49772: The Events Calendar Blind SQL Injection (CVSS 9.3)
ID: aa7a5b76-0793-50a1-967f-006b40498d74
STIX ID: report--aa7a5b76-0793-50a1-967f-006b40498d74
Feed Name: CosmicBytez Labs
Threat Score
**Executive Summary:** A critical (CVSS 9.3) blind SQL injection (CVE-2026-49772) was disclosed in The Events Calendar plugin (versions 6.15.12–6.16.2), allowing unauthenticated attackers to exfiltrate WordPress database contents (including admin credential hashes, user PII, and stored API keys) via boolean- or time-based SQLi techniques; immediate patching to versions after 6.16.2, deploying WAF rules, or disabling the plugin are recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
