CVE-2025-12192
BaseFortify
Publication date: 2025-11-05
Last updated on: 2025-11-06
Assigner: Wordfence
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| the_events_calendar | plugin | 6.15.9 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-697 | The product compares two entities in a security-relevant context, but the comparison is incorrect. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The Events Calendar plugin for WordPress has a vulnerability in versions up to 6.15.9 where its sysinfo REST endpoint uses a loose comparison to check a provided key against a stored opt-in key. This allows unauthenticated attackers to send a boolean value and retrieve the full system report if the setting to automatically share system information with The Events Calendar support team is enabled.
How can this vulnerability impact me? :
This vulnerability can lead to information disclosure, allowing attackers without authentication to access detailed system reports. This could expose sensitive system information that might be used for further attacks or reconnaissance.