Metrics
Affected Vendors & Products
Fri, 12 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Fri, 12 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Dec 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 7.2.2.2 via the 'get_location' action due to insufficient restrictions on which locations can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft event locations that they should not have access to. | |
| Title | Events Manager <= 7.2.2.2 - Unauthenticated Information Exposure | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-12-12T11:15:50.794Z
Updated: 2025-12-12T15:31:14.953Z
Reserved: 2025-10-28T15:15:50.054Z
Link: CVE-2025-12408
Updated: 2025-12-12T14:39:05.078Z
Status : Awaiting Analysis
Published: 2025-12-12T12:15:45.587
Modified: 2025-12-12T15:17:31.973
Link: CVE-2025-12408
No data.