Known CVE
The Events Calendar <= 6.15.2 - Information Disclosure
The Events Calendar WordPress plugin <= 6.15.2 contains an information disclosure vulnerability caused by REST endpoint exposure, letting unauthenticated attackers extract data about password-protected vendors or venues, exploit requires no authentication.
CVE-2025-9808
Medium2025
cve2025 · wordpress · wp-plugin · wpscan · the-events-calendar · unauth · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website