CVE-2025-12175: The Events Calendar <= 6.15.9 - Missing Authorization to Authenticated (Subscriber+) Draft Event Title/QR Code Exposure
The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'tecqrcodemodal' AJAX endpoint in all versions up to, and including, 6.15.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view draft event names and generate/view QR codes for them.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12175?
CVE-2025-12175 has a moderate severity level due to the unauthorized access potential for authenticated attackers.
How do I fix CVE-2025-12175?
To fix CVE-2025-12175, upgrade The Events Calendar plugin to version 6.15.10 or higher.
Who is affected by CVE-2025-12175?
CVE-2025-12175 affects all versions of The Events Calendar plugin up to and including 6.15.9.
What type of vulnerability is CVE-2025-12175?
CVE-2025-12175 is a security vulnerability that allows unauthorized access due to a missing capability check.
Can CVE-2025-12175 be exploited remotely?
Yes, CVE-2025-12175 can be exploited remotely by authenticated users with Subscriber-level access.