cleantalk
Vulnerabilities and Security Researches

Pretty Google Calendar, CVE-2025-12898

CVE, Research URL

CVE-2025-12898

Published on
Dec 20, 2025
Research Description
The Pretty Google Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the pgcal_ajax_handler() function in all versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to retrieve the Google API key set in the plugin's settings.
Affected versions
max 2.0.0.
Status
vulnerable