
Import Social Events Security & Risk Analysis
wordpress.org/plugins/import-facebook-eventsImport Facebook events into your WordPress website and/or Event Calendar. Nice Display with shortcode & Event widget.
Is Import Social Events Safe to Use in 2026?
Generally Safe
Score 99/100Import Social Events has a strong security track record. Known vulnerabilities have been patched promptly.
The "import-facebook-events" plugin v1.8.8 exhibits a mixed security posture. While it demonstrates good practices with a high percentage of prepared SQL statements and properly escaped output, there are notable concerns regarding its attack surface. Specifically, two of its three AJAX handlers lack authentication checks, presenting a direct entry point for potential unauthorized actions. The presence of unsanitized paths in taint analysis, though not currently rated as critical or high severity, warrants attention as it suggests potential avenues for manipulation.
The vulnerability history shows a single medium-severity CVE for Cross-Site Scripting, which is currently patched. However, the timing of this last vulnerability (May 2025) is unusual, potentially indicating historical data rather than current real-world exploitation. Despite the generally positive code signals, the unprotected AJAX endpoints are a significant weakness that could be exploited by an attacker if further vulnerabilities are discovered in the plugin's logic or if the plugin's functionality is misused.
In conclusion, while the plugin has strengths in secure coding practices for SQL and output handling, the unprotected AJAX entry points introduce a tangible risk. The past XSS vulnerability, even if patched, highlights a past weakness that attackers might seek to exploit again in different forms. It is crucial to address the authentication checks on AJAX handlers to mitigate the current risk.
Key Concerns
- AJAX handlers without authentication checks
- Taint flows with unsanitized paths
- Medium severity vulnerability history (XSS)
Import Social Events Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Import Social Events <= 1.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Import Social Events Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Import Social Events Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 36
Scheduled Events 1
Maintenance & Trust
Import Social Events Maintenance & Trust
Maintenance Signals
Community Trust
Import Social Events Alternatives
WP Event Aggregator: Import Eventbrite events, Meetup events, social events and any iCal Events into Event Calendar
wp-event-aggregator
Xylus WP Event Aggregator: Easy way to import Eventbrite events, MeetUp events, Social site Events into your WordPress Event Calendar.
Import Eventbrite Events
import-eventbrite-events
Import Eventbrite Events into WordPress website and/or Event Calendar. Nice Display with shortcode & Event widget.
XT Event Widget for Social Events
xt-facebook-events
Easiest way to display Facebook events from your Facebook page to your website using widget or shortcode.
Import Meetup Events – Meetup Sync & Event Aggregator for WordPress
import-meetup-events
Automatically import and sync Meetup.com events into WordPress without a Meetup Pro account. Works with The Events Calendar, Events Manager, EventON, …
Eventissimo
eventissimo
Create and organize events into your site. Your events also automatically created on Facebook. Import your Facebook Events.
Import Social Events Developer Profile
13 plugins · 110K total installs
How We Detect Import Social Events
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/import-facebook-events/css/admin.css/wp-content/plugins/import-facebook-events/css/frontend.css/wp-content/plugins/import-facebook-events/js/admin.js/wp-content/plugins/import-facebook-events/js/frontend.js/wp-content/plugins/import-facebook-events/js/admin.js/wp-content/plugins/import-facebook-events/js/frontend.jsimport-facebook-events/css/admin.css?ver=import-facebook-events/css/frontend.css?ver=import-facebook-events/js/admin.js?ver=import-facebook-events/js/frontend.js?ver=HTML / DOM Fingerprints
import_facebook_events_admin_pageimport_facebook_events_admin_wrapper<!-- Import Facebook Events Plugin --><!-- Import Facebook Events -->data-ife-noncedata-facebook-urldata-ajax-urlImportFacebookEventsAdminife_ajax_object/wp-json/import-facebook-events/v1/get_events/wp-json/import-facebook-events/v1/save_settings/wp-json/import-facebook-events/v1/delete_event[import_facebook_event_list][import_facebook_events_widget]