PT-2025-50920 · WordPress · Events Manager – Calendar

Thinnawarth Mathuros

·

Published

2025-12-12

·

Updated

2025-12-12

·

CVE-2025-12407

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress versions prior to 7.2.2.3
Description The software is susceptible to a Cross-Site Request Forgery (CSRF) issue. This is caused by inadequate or missing nonce validation on the location delete action. An unauthenticated attacker could potentially delete locations by exploiting this flaw, provided they can trick a site administrator into performing an action, such as clicking a malicious link.
Recommendations Update The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress to version 7.2.2.3 or later.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-12407

Affected Products

Events Manager – Calendar