Record summary

CVE-2025-9808 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract information about password-protected vendors or venues.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 16, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 6.15.2affected

Nuclei templates

1
ProjectDiscoveryMEDIUMThe Events Calendar <= 6.15.2 - Information Disclosure

The Events Calendar WordPress plugin <= 6.15.2 contains an information disclosure vulnerability caused by REST endpoint exposure, letting unauthenticated attackers extract data about password-protected vendors or venues, exploit requires no authentication.

Impact

Unauthenticated attackers can access sensitive information about password-protected vendors or venues.

Remediation

Update to the latest version beyond 6.15.2

Authorszer0p0int
Template tagscvecve2025wordpresswp-pluginwpscanthe-events-calendarunauthvuln
Shodan: http.html:"/wp-content/plugins/the-events-calendar/"
FOFA: body="/wp-content/plugins/the-events-calendar/"

Source: ProjectDiscovery

References

3