CVE-2026-49772 is a critical unauthenticated blind SQL injection vulnerability in The Events Calendar WordPress plugin by Liquid Web / StellarWP. The flaw affects versions 6.15.12 through 6.16.2 and stems from improper neutralization of special elements used in SQL commands. Available reporting indicates the issue is associated with the plugin’s custom database query handling and may relate to weaknesses in its custom query construction layer. The vulnerability is exploitable remotely over the network without authentication or user interaction, allowing an attacker to inject SQL into backend queries and infer database contents through blind techniques such as boolean-based or time-based responses.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a standalone Python proof-of-concept exploit for CVE-2026-49772, an unauthenticated blind SQL injection affecting The Events Calendar WordPress plugin versions 6.15.12 through 6.16.2. The main exploit file is CVE-2026-49772.py, which uses only Python standard-library modules and implements a full blind-SQLi extraction workflow against the plugin’s experimental REST endpoint /wp-json/tec/v1/events. The exploit injects into the order parameter of a request shaped like /wp-json/tec/v1/events?orderby=event_date&order=<payload>, while also sending the required X-TEC-EEA header value to pass the endpoint gate. Capability-wise, this is more than a simple checker. It supports vulnerability checking, reconnaissance, dumping WordPress users and password hashes, dumping wp_usermeta, dumping arbitrary tables with automatic column discovery, and extracting arbitrary scalar SELECT results. The code wraps the injection into an oracle abstraction that supports both boolean-based and time-based inference, with multithreading for faster extraction. The README explicitly states the impact is read-only database disclosure: no writes, no stacked queries, and no direct command execution. Repository structure is small and focused: one primary Python exploit, documentation files, and a Docker lab. The Docker directory contains a compose-based vulnerable WordPress/MariaDB environment, a setup shell script, and a seeded SQL snapshot for reproducible testing. The lab exposes WordPress on localhost:8080 and installs the vulnerable plugin from a bundled ZIP. Overall, this is a real, operational exploit repository intended for authorized security testing and research, not merely a detector or README-only advisory.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A blind SQL injection vulnerability in Liquid Web / StellarWP The Events Calendar WordPress plugin affecting versions 6.15.12 through 6.16.2.
A critical unauthenticated blind SQL injection vulnerability in The Events Calendar WordPress plugin affecting versions 6.15.12 through 6.16.2, enabling remote attackers to infer and extract database contents without credentials.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.