The Events Calendar, CVE-2025-12192
- CVE, Research URL
- Home page URL
- Application
- Published on
- Nov 05, 2025
- Research Description
- The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.9. The sysinfo REST endpoint compares the provided key to the stored opt-in key using a loose comparison, allowing unauthenticated attackers to send a boolean value and obtain the full system report whenever "Yes, automatically share my system information with The Events Calendar support team" setting is enabled.
- Affected versions
-
max 6.15.10.
- Status
-
vulnerable