CVE-2025-9808
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-9808 is an Information Exposure vulnerability in The Events Calendar plugin for WordPress, classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). All versions up to and including 6.15.2 are affected. The flaw allows unauthenticated attackers to extract information about password-protected vendors or venues via the plugin's REST endpoint. It was published on September 16, 2025, with Wordfence as the assigning authority, and carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is improper access control on the plugin's REST API endpoint, which fails to enforce password-protection restrictions before returning data about vendors or venues (CWE-200). An unauthenticated attacker can send a crafted HTTP GET request to the exposed REST endpoint to retrieve metadata or content details for resources that should be gated behind a password. No authentication, elevated privileges, or user interaction is required, making the attack surface broad and trivially accessible over the network. A patch was committed to the WordPress plugin repository at changeset 3359403 (Wordfence, WordPress SVN).

Impact

Successful exploitation results in unauthorized disclosure of information about password-protected vendors or venues managed through The Events Calendar plugin, impacting confidentiality. There is no integrity or availability impact. While the exposed data is limited in scope (vendor/venue metadata rather than full site credentials), it could enable targeted reconnaissance or social engineering against site administrators or event organizers. The vulnerability does not provide a direct path to lateral movement or remote code execution.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running The Events Calendar plugin version 6.15.2 or earlier using tools like WPScan, Shodan, or Nuclei with the available detection template.
  2. Identify REST endpoint: Locate the plugin's REST API endpoint (typically under /wp-json/tribe/) that handles vendor or venue data.
  3. Send unauthenticated request: Issue an HTTP GET request to the REST endpoint for a password-protected vendor or venue resource without providing any authentication credentials or the resource password.
  4. Extract exposed data: Parse the API response to retrieve metadata or content details about the password-protected resource that should not be publicly accessible (Wordfence).

Indicators of compromise

  • Network: Unusual or repeated unauthenticated HTTP GET requests to WordPress REST API endpoints under /wp-json/tribe/ paths, particularly targeting vendor or venue resources.
  • Logs: Web server access logs showing requests to REST endpoints for password-protected resources returning HTTP 200 responses without authentication headers or session cookies.
  • Logs: Automated scanning patterns (high-frequency requests, sequential resource ID enumeration) originating from a single IP or user-agent string associated with tools like Nuclei or WPScan.

Mitigation and workarounds

Update The Events Calendar plugin to version 6.15.3 or later, which includes the fix committed in WordPress SVN changeset 3359403. Site administrators should apply the update immediately via the WordPress admin dashboard or WP-CLI. As a temporary workaround, consider restricting access to the WordPress REST API for unauthenticated users using a security plugin or server-level configuration, though upgrading is the definitive remediation (Wordfence, WordPress SVN).

Community reactions

Wordfence included CVE-2025-9808 in its weekly WordPress vulnerability report for September 15–21, 2025, and Sucuri referenced it in its September 2025 vulnerability patch roundup. Community interest has been modest, consistent with the Medium severity rating. Nuclei templates for automated detection were contributed to the ProjectDiscovery repository, reflecting practitioner interest in scanning for this issue at scale (Wordfence Blog, Sucuri Blog).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-12968HIGH8.8
  • product-addons
NoYesJul 22, 2026
CVE-2026-12987HIGH7.5
  • events-manager
NoYesJul 22, 2026
CVE-2026-1771HIGH7.2
  • mapsvg-lite-interactive-vector-maps
NoYesJul 21, 2026
CVE-2025-13146MEDIUM6.5
  • contact-form-7-dynamic-text-extension
NoNoJul 22, 2026
CVE-2026-14322MEDIUM5.3
  • timetics
NoYesJul 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management