Import Social Events Security & Risk Analysis

wordpress.org/plugins/import-facebook-events

Import Facebook events into your WordPress website and/or Event Calendar. Nice Display with shortcode & Event widget.

3K active installs v1.8.8 PHP 5.3+ WP 4.0+ Updated Jan 6, 2026
calendareventsfacebookfacebook-eventimport
99
A · Safe
CVEs total1
Unpatched0
Last CVEMay 19, 2025
Safety Verdict

Is Import Social Events Safe to Use in 2026?

Generally Safe

Score 99/100

Import Social Events has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: May 19, 2025Updated 2mo ago
Risk Assessment

The "import-facebook-events" plugin v1.8.8 exhibits a mixed security posture. While it demonstrates good practices with a high percentage of prepared SQL statements and properly escaped output, there are notable concerns regarding its attack surface. Specifically, two of its three AJAX handlers lack authentication checks, presenting a direct entry point for potential unauthorized actions. The presence of unsanitized paths in taint analysis, though not currently rated as critical or high severity, warrants attention as it suggests potential avenues for manipulation.

The vulnerability history shows a single medium-severity CVE for Cross-Site Scripting, which is currently patched. However, the timing of this last vulnerability (May 2025) is unusual, potentially indicating historical data rather than current real-world exploitation. Despite the generally positive code signals, the unprotected AJAX endpoints are a significant weakness that could be exploited by an attacker if further vulnerabilities are discovered in the plugin's logic or if the plugin's functionality is misused.

In conclusion, while the plugin has strengths in secure coding practices for SQL and output handling, the unprotected AJAX entry points introduce a tangible risk. The past XSS vulnerability, even if patched, highlights a past weakness that attackers might seek to exploit again in different forms. It is crucial to address the authentication checks on AJAX handlers to mitigate the current risk.

Key Concerns

  • AJAX handlers without authentication checks
  • Taint flows with unsanitized paths
  • Medium severity vulnerability history (XSS)
Vulnerabilities
1

Import Social Events Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-48256medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Import Social Events <= 1.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 19, 2025 Patched in 1.8.6 (10d)
Code Analysis
Analyzed Mar 16, 2026

Import Social Events Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
32 prepared
Unescaped Output
8
554 escaped
Nonce Checks
11
Capability Checks
1
File Operations
4
External Requests
10
Bundled Libraries
0

SQL Query Safety

94% prepared34 total queries

Output Escaping

99% escaped562 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

8 flows3 with unsanitized paths
admin_page (includes\class-import-facebook-events-admin.php:169)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Import Social Events Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 3

authwp_ajax_ife_load_paged_eventsincludes\class-import-facebook-events-ajax.php:25
noprivwp_ajax_ife_load_paged_eventsincludes\class-import-facebook-events-ajax.php:26
authwp_ajax_ife_render_terms_by_pluginincludes\class-import-facebook-events-common.php:32

Shortcodes 1

[facebook_events] includes\class-import-facebook-events-cpt.php:80
WordPress Hooks 36
actioninitblocks\facebook-events\index.php:96
actioninitimport-facebook-events.php:58
actionplugins_loadedimport-facebook-events.php:59
actionwp_enqueue_scriptsimport-facebook-events.php:60
actionwp_enqueue_scriptsimport-facebook-events.php:61
actionadmin_footerincludes\class-ife-plugin-deactivation.php:41
actioninitincludes\class-import-facebook-events-admin.php:42
actioninitincludes\class-import-facebook-events-admin.php:43
actionadmin_noticesincludes\class-import-facebook-events-admin.php:44
actionife_display_all_noticeincludes\class-import-facebook-events-admin.php:45
actionadmin_initincludes\class-import-facebook-events-admin.php:46
actionife_delete_past_events_cronincludes\class-import-facebook-events-admin.php:47
actionadmin_menuincludes\class-import-facebook-events-admin.php:48
filtersubmenu_fileincludes\class-import-facebook-events-admin.php:49
actionadmin_enqueue_scriptsincludes\class-import-facebook-events-admin.php:50
actionadmin_enqueue_scriptsincludes\class-import-facebook-events-admin.php:51
actionadmin_action_ife_view_import_historyincludes\class-import-facebook-events-admin.php:52
actionadmin_initincludes\class-import-facebook-events-admin.php:53
actionadmin_initincludes\class-import-facebook-events-common.php:33
actionadmin_initincludes\class-import-facebook-events-common.php:34
actionife_render_pro_noticeincludes\class-import-facebook-events-common.php:35
actionadmin_initincludes\class-import-facebook-events-common.php:36
actioninitincludes\class-import-facebook-events-cpt.php:71
actioninitincludes\class-import-facebook-events-cpt.php:72
actionadd_meta_boxesincludes\class-import-facebook-events-cpt.php:73
actionsave_postincludes\class-import-facebook-events-cpt.php:74
filtermanage_facebook_events_posts_columnsincludes\class-import-facebook-events-cpt.php:76
actionmanage_posts_custom_columnincludes\class-import-facebook-events-cpt.php:77
filterthe_contentincludes\class-import-facebook-events-cpt.php:79
actionadmin_post_ife_facebook_authorize_actionincludes\class-import-facebook-events-fb-authorize.php:40
actionadmin_post_ife_facebook_authorize_callbackincludes\class-import-facebook-events-fb-authorize.php:41
actioninitincludes\class-import-facebook-events-manage-import.php:32
actionadmin_initincludes\class-import-facebook-events-manage-import.php:33
actionadmin_initincludes\class-import-facebook-events-manage-import.php:34
actionadmin_initincludes\class-import-facebook-events-manage-import.php:35
actionadmin_initincludes\class-import-facebook-events-manage-import.php:36

Scheduled Events 1

ife_delete_past_events_cron
Maintenance & Trust

Import Social Events Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 6, 2026
PHP min version5.3
Downloads247K

Community Trust

Rating96/100
Number of ratings114
Active installs3K
Developer Profile

Import Social Events Developer Profile

Xylus Themes

13 plugins · 110K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
105 days
View full developer profile
Detection Fingerprints

How We Detect Import Social Events

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/import-facebook-events/css/admin.css/wp-content/plugins/import-facebook-events/css/frontend.css/wp-content/plugins/import-facebook-events/js/admin.js/wp-content/plugins/import-facebook-events/js/frontend.js
Script Paths
/wp-content/plugins/import-facebook-events/js/admin.js/wp-content/plugins/import-facebook-events/js/frontend.js
Version Parameters
import-facebook-events/css/admin.css?ver=import-facebook-events/css/frontend.css?ver=import-facebook-events/js/admin.js?ver=import-facebook-events/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
import_facebook_events_admin_pageimport_facebook_events_admin_wrapper
HTML Comments
<!-- Import Facebook Events Plugin --><!-- Import Facebook Events -->
Data Attributes
data-ife-noncedata-facebook-urldata-ajax-url
JS Globals
ImportFacebookEventsAdminife_ajax_object
REST Endpoints
/wp-json/import-facebook-events/v1/get_events/wp-json/import-facebook-events/v1/save_settings/wp-json/import-facebook-events/v1/delete_event
Shortcode Output
[import_facebook_event_list][import_facebook_events_widget]
FAQ

Frequently Asked Questions about Import Social Events