PT-2025-45099 · WordPress · The Events Calendar

Michael Mazzolini

·

Published

2025-11-05

·

Updated

2025-11-05

·

CVE-2025-12192

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Events Calendar plugin for WordPress versions through 6.15.9
Description The Events Calendar plugin for WordPress has an information disclosure issue. The sysinfo REST endpoint performs a weak comparison between the provided key and the stored opt-in key. This allows unauthenticated attackers to obtain the full system report when the "Yes, automatically share my system information with The Events Calendar support team" setting is enabled. The vulnerable endpoint is /sysinfo. The issue arises from the comparison of the key parameter.
Recommendations Versions prior to 6.15.9 are affected.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-12192

Affected Products

The Events Calendar