WordPress The Events Calendar plugin 6.15.12-6.16.2 - SQL Injection vulnerability
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-49772. PoCs published by joshuavanderpoll.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-49772, an unauthenticated blind SQL injection vulnerability in The Events Calendar WordPress plugin (versions 6.15.12 to 6.16.2). The exploit leverages an ORDER BY injection via the `order` parameter on the `/wp-json/tec/v1/events` endpoint, supporting both time-based and boolean-based techniques for data extraction.
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6.15.12 through 6.16.2.
Exploits (1)
This repository contains a functional exploit for CVE-2026-49772, an unauthenticated blind SQL injection vulnerability in The Events Calendar WordPress plugin (versions 6.15.12 to 6.16.2). The exploit leverages an ORDER BY injection via the `order` parameter on the `/wp-json/tec/v1/events` endpoint, supporting both time-based and boolean-based techniques for data extraction.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L