CVE · Medium

CVE-2025-12408 — Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.2.2.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-12408 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.2.2.3 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 7.2.2.3 7.2.2.3 2025-12-11

CVE-2025-12408

The Events Manager plugin for WordPress contains a flaw in versions up through 7.2.2.2. Specifically, the 'get_location' action lacks sufficient controls over which location data can be retrieved, allowing unauthorized users to potentially access sensitive information from protected or restricted event locations without proper authentication. As a result, attackers may obtain confidential details from events intended to remain private.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.