
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-9808 is an Information Exposure vulnerability in The Events Calendar plugin for WordPress, classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). All versions up to and including 6.15.2 are affected. The flaw allows unauthenticated attackers to extract information about password-protected vendors or venues via the plugin's REST endpoint. It was published on September 16, 2025, with Wordfence as the assigning authority, and carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is improper access control on the plugin's REST API endpoint, which fails to enforce password-protection restrictions before returning data about vendors or venues (CWE-200). An unauthenticated attacker can send a crafted HTTP GET request to the exposed REST endpoint to retrieve metadata or content details for resources that should be gated behind a password. No authentication, elevated privileges, or user interaction is required, making the attack surface broad and trivially accessible over the network. A patch was committed to the WordPress plugin repository at changeset 3359403 (Wordfence, WordPress SVN).
Successful exploitation results in unauthorized disclosure of information about password-protected vendors or venues managed through The Events Calendar plugin, impacting confidentiality. There is no integrity or availability impact. While the exposed data is limited in scope (vendor/venue metadata rather than full site credentials), it could enable targeted reconnaissance or social engineering against site administrators or event organizers. The vulnerability does not provide a direct path to lateral movement or remote code execution.
/wp-json/tribe/) that handles vendor or venue data./wp-json/tribe/ paths, particularly targeting vendor or venue resources.Update The Events Calendar plugin to version 6.15.3 or later, which includes the fix committed in WordPress SVN changeset 3359403. Site administrators should apply the update immediately via the WordPress admin dashboard or WP-CLI. As a temporary workaround, consider restricting access to the WordPress REST API for unauthenticated users using a security plugin or server-level configuration, though upgrading is the definitive remediation (Wordfence, WordPress SVN).
Wordfence included CVE-2025-9808 in its weekly WordPress vulnerability report for September 15–21, 2025, and Sucuri referenced it in its September 2025 vulnerability patch roundup. Community interest has been modest, consistent with the Medium severity rating. Nuclei templates for automated detection were contributed to the ProjectDiscovery repository, reflecting practitioner interest in scanning for this issue at scale (Wordfence Blog, Sucuri Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."