CVE · Medium

CVE-2025-12192 — The Events Calendar [the-events-calendar] < 6.15.10

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-12192 The Events Calendar [the-events-calendar] < 6.15.10 Incorrect Comparison Medium 5.3 < 6.15.10 6.15.10 2025-11-04

CVE-2025-12192

The Events Calendar plugin for WordPress has an issue in versions 6.15.9 and earlier where the sysinfo REST endpoint does not properly validate user input when checking against stored opt-in keys. This vulnerability allows anyone to obtain a full system report if the "Share system information with support" setting is turned on, regardless of authentication status. The comparison used by the plugin is too lenient, making it easy for attackers to exploit this weakness.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.