
Upcoming Events Lists Security & Risk Analysis
wordpress.org/plugins/upcoming-events-listsA WordPress plugin to show a list of upcoming events on the front-end.
Is Upcoming Events Lists Safe to Use in 2026?
Mostly Safe
Score 78/100Upcoming Events Lists is generally safe to use. 1 past CVE were resolved. Keep it updated.
The "upcoming-events-lists" plugin version 1.4.0 exhibits a mixed security posture. On the positive side, the static analysis reveals good practices such as 100% of SQL queries using prepared statements and the presence of nonce checks. The absence of dangerous functions, file operations, and external HTTP requests is also reassuring, suggesting a limited potential for certain types of attacks. However, the critical weakness lies in the vulnerability history. The presence of one known medium-severity CVE, "Exposure of Sensitive Information to an Unauthorized Actor," which is currently unpatched, represents a significant risk. The fact that this is the only known vulnerability and it's recent is concerning, as it indicates a potential for unauthorized access to sensitive data if exploited. The code analysis also highlights a concern with output escaping, as only 50% of outputs are properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities, although no direct taint flows were detected. The plugin has a small attack surface with only one shortcode, and importantly, no unprotected entry points identified in the static analysis.
Key Concerns
- Unpatched medium severity CVE
- Half of outputs unescaped
Upcoming Events Lists Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Upcoming Events Lists <= 1.4.0 - Authenticated (Subscriber+) Insecure Direct Object Reference
Upcoming Events Lists Code Analysis
Output Escaping
Upcoming Events Lists Attack Surface
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
Upcoming Events Lists Maintenance & Trust
Maintenance Signals
Community Trust
Upcoming Events Lists Alternatives
External Events Calendar
external-events-calendar
This plugin adds a basic "upcoming events" calendar of links to Wordpress.
Simple Calendar – Google Calendar Plugin
google-calendar-events
Add Google Calendar events to your WordPress site in minutes. Beautiful calendar displays. Mobile responsive.
Events Widgets For Elementor And The Events Calendar
events-widgets-for-elementor-and-the-events-calendar
The Events Calendar Elementor widgets help you manage and display an upcoming events list with date, time, venue and event ticket booking details.
ICS Calendar
ics-calendar
Add the calendar you already use to Any WordPress site! Google Calendar, Microsoft 365, iCloud and more… no API keys or complicated setup required.
Show Eventbrite Events – Event Feed for Eventbrite
event-feed-for-eventbrite
Show Eventbrite events easily with the Eventbrite WordPress plugin. Eventbrite widget integration without imports or complicated setup.
Upcoming Events Lists Developer Profile
5 plugins · 36K total installs
How We Detect Upcoming Events Lists
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/upcoming-events-lists/assets/css/admin-style.css/wp-content/plugins/upcoming-events-lists/assets/js/admin.js/wp-content/plugins/upcoming-events-lists/assets/js/admin.jsupcoming-events-lists/assets/css/admin-style.css?ver=upcoming-events-lists/assets/js/admin.js?ver=HTML / DOM Fingerprints
upcoming-events-listsdata-post-id/wp-json/upcoming-events-lists/v1/events[upcoming_events_lists]