CVE-2025-12192
The Events Calendar plugin for WordPress has an issue in versions 6.15.9 and earlier where the sysinfo REST endpoint does not properly validate user input when checking against stored opt-in keys. This vulnerability allows anyone to obtain a full system report if the "Share system information with support" setting is turned on, regardless of authentication status. The comparison used by the plugin is too lenient, making it easy for attackers to exploit this weakness.
Based on public CVE data (MITRE/NVD).