Description
The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract information about password-protected vendors or venues.
Published: 2025-09-16
Score: 5.3 Medium
EPSS: 1.2% Low
KEV: No
Impact: Information disclosure
Action: Patch
AI Analysis

Impact

The Events Calendar plugin for WordPress is vulnerable to information exposure in versions up to and including 6.15.2 due to a flaw in the REST endpoint. The weakness, identified as CWE‑200, allows attackers to read data that should be protected by password protection on vendors or venues. The exposure can reveal sensitive data such as vendor identities, venue details, or other private attributes, potentially compromising confidentiality of site content.

Affected Systems

StellarWP’s The Events Calendar plugin, versions 6.15.2 and earlier, running on WordPress sites are affected. The vulnerability is tied to the plugin’s REST API component and is present in all releases up to the specified version.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score of 1% suggests a relatively low probability of exploitation but it is not zero. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation. Attackers can reach the flaw by sending unauthenticated requests to the plugin’s REST endpoint, as the authentication check is missing in the endpoint logic. If successful, attackers could retrieve protected information without any privilege.

Generated by OpenCVE AI on April 22, 2026 at 14:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch or upgrade to The Events Calendar version 6.15.3 or later.
  • If an immediate upgrade is not feasible, restrict access to the plugin’s REST endpoints by disabling them or enforcing authentication, for example by adding a rule to deny all GET/POST requests to /wp-json/events/ when the requester is not logged in.
  • Implement a Web Application Firewall rule to block or rate‑limit unauthenticated requests to the affected REST paths, reducing the risk of automated exploitation.

Generated by OpenCVE AI on April 22, 2026 at 14:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-29359 The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract information about password-protected vendors or venues.
History

Wed, 17 Sep 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Theeventscalendar
Theeventscalendar the Events Calendar
Wordpress
Wordpress wordpress
Vendors & Products Theeventscalendar
Theeventscalendar the Events Calendar
Wordpress
Wordpress wordpress

Tue, 16 Sep 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Sep 2025 05:45:00 +0000

Type Values Removed Values Added
Description The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract information about password-protected vendors or venues.
Title The Events Calendar <= 6.15.2 - Missing Authorization to Unauthenticated Password-Protected Information Disclosure
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Theeventscalendar The Events Calendar
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:35:38.363Z

Reserved: 2025-09-01T15:49:44.923Z

Link: CVE-2025-9808

cve-icon Vulnrichment

Updated: 2025-09-16T19:15:58.027Z

cve-icon NVD

Status : Deferred

Published: 2025-09-16T06:16:06.463

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-9808

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T14:30:18Z

Weaknesses