All verified exploits

CVE-2026-3585 The Events Calendar Authenticated LFI via CSV Import

Deterministic high WordPress Added cve-verified-cve-2026-3585

Detects The Events Calendar WordPress plugin at version 6.15.17 or earlier, where the ajax_create_import function accepts arbitrary file paths via the CSV import feature without path validation. An authenticated attacker with Author-level access can read any file on the server — including wp-config.php, /etc/passwd, and database credentials — by pointing the Event Aggregator CSV importer at a traversal path.

Related WordPress exploits

Is your app exploitable through CVE-2026-3585?

Scan your domain free