CVE-2025-8091

MEDIUM

EventON Lite <2.4.6 - Info Disclosure

Title source: llm

Description

The EventON Lite plugin for WordPress is vulnerable to Information Exposure in all versions less than, or equal to, 2.4.6 via the add_single_eventon and add_eventon shortcodes due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft posts that they should not have access to.

Exploits (1)

nomisec WRITEUP
by MooseLoveti · poc
https://github.com/MooseLoveti/EventON-Lite-CVE-Report

Scores

CVSS v3 4.3
EPSS 0.0009
EPSS Percentile 24.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (2)
ashanjay/EventON – Events Calendar < 2.4.6
ashanjay/EventON – Events Calendar < 2.4.7
Published Aug 15, 2025
Tracked Since Feb 18, 2026