VulnSea

stellarwp has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 8.7 (high), with 2 rated critical. Most affected products: The Events Calendar (2), Event Tickets and Registration (1), WPComplete (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.7
Publish → KEV
Last 90 days
4 prev 0

Products

  • The Events Calendar 2
  • Event Tickets and Registration 1
  • WPComplete 1
4
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

stellarwp vulnerabilities

CVEs affecting stellarwp, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-77820Medium· 6.4
2d ago

The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty' Shortcode Attribute in all versions up to, and including, 2.9.9.0 due to insufficient input sanitization and output escaping

The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty' Shortcode Attribute in all versions up to, and including, 2.9.9.0 due to insufficient input sanitization and output escaping. This makes it poss…

Sunlitstellarwp · WPCompleteEPSS 0.24%via NVD
CVE-2026-78159Critical· 9.8PoC
1w ago

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a…

Abyssalstellarwp · The Events CalendarEPSS 0.76%via NVD
CVE-2026-78006Critical· 9.8PoC
1w ago

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance,…

Abyssalstellarwp · The Events CalendarEPSS 0.78%via NVD
CVE-2026-3174High· 7.5
1w ago

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it …

Twilightstellarwp · Event Tickets and RegistrationEPSS 0.26%via NVD
stellarwp vulnerabilities (CVEs) · VulnSea