CVE-2025-12498: EventPrime – Events Calendar, Bookings and Tickets <= 4.2.0.0 - Missing Authorization to Authenticated (Subscriber+) Booking Note Creation
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized booking note creation due to a missing capability check on the 'bookingaddnotes' function in all versions up to, and including, 4.2.0.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add a note to the backend view of any booking.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12498?
CVE-2025-12498 has been classified as a medium severity vulnerability due to the potential for unauthorized access to booking notes.
How do I fix CVE-2025-12498?
To fix CVE-2025-12498, update the EventPrime – Events Calendar, Bookings and Tickets plugin to version 4.2.0.1 or higher.
Who is affected by CVE-2025-12498?
CVE-2025-12498 affects all versions of the EventPrime – Events Calendar, Bookings and Tickets plugin up to and including version 4.2.0.0.
What type of vulnerability is CVE-2025-12498?
CVE-2025-12498 is a security vulnerability that allows unauthorized users to create booking notes due to a missing capability check.
Can CVE-2025-12498 lead to data leakage?
Yes, CVE-2025-12498 can potentially lead to data leakage by allowing unauthorized users to add booking notes.