CVE-2025-63007: WordPress EventPrime plugin <= 4.2.4.1 - Sensitive Data Exposure vulnerability
Published Dec 9, 2025
·Updated
Insertion of Sensitive Information Into Sent Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Retrieve Embedded Sensitive Data.This issue affects EventPrime: from n/a through <= 4.2.4.1.
Affected Software
2 affected components
Metagauss EventPrime<=4.2.4.1
wordpress/EventPrime<=4.2.4.1
Event History
Dec 9, 2025
CVE Published
via MITRE·02:52 PM
Data Sourced
via MITRE·02:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-63007?
CVE-2025-63007 has not been officially assigned a severity rating, but it involves sensitive information exposure, which is typically considered critical.
2
How do I fix CVE-2025-63007?
To mitigate CVE-2025-63007, upgrade Metagauss EventPrime to a version higher than 4.2.4.1.
3
What type of vulnerability is CVE-2025-63007?
CVE-2025-63007 is an Insertion of Sensitive Information Into Sent Data vulnerability.
4
What versions of Metagauss EventPrime are affected by CVE-2025-63007?
CVE-2025-63007 affects Metagauss EventPrime versions up to and including 4.2.4.1.
5
Can CVE-2025-63007 be exploited remotely?
Yes, CVE-2025-63007 can potentially be exploited remotely if an attacker has access to the application's resources.