CVE-2025-9808
The Events Calendar <= 6.15.2 - Missing Authorization to Unauthenticated Password-Protected Information Disclosure
Record summary
CVE-2025-9808 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract information about password-protected vendors or venues.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 16, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
The Events CalendarBrowse stellarwp / The Events CalendarDefault status: unaffected | CVE List | Through 6.15.2 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMThe Events Calendar <= 6.15.2 - Information Disclosure
The Events Calendar WordPress plugin <= 6.15.2 contains an information disclosure vulnerability caused by REST endpoint exposure, letting unauthenticated attackers extract data about password-protected vendors or venues, exploit requires no authentication.
Impact
Unauthenticated attackers can access sensitive information about password-protected vendors or venues.
Remediation
Update to the latest version beyond 6.15.2
Source: ProjectDiscovery