CVE-2025-9808: The Events Calendar <= 6.15.2 - Missing Authorization to Unauthenticated Password-Protected Information Disclosure
Published Sep 16, 2025
·Updated
The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract information about password-protected vendors or venues.
Affected Software
1 affected component
Modern Tribe The Events Calendar<=6.15.2
Event History
Sep 16, 2025
CVE Published
via MITRE·05:25 AM
Data Sourced
via MITRE·05:25 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Apr 12, 58019
Event
via FIRST·05:48 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-9808?
CVE-2025-9808 is classified as a medium severity vulnerability due to the potential for information exposure.
2
How do I fix CVE-2025-9808?
To fix CVE-2025-9808, update The Events Calendar plugin to version 6.15.3 or later.
3
Who is affected by CVE-2025-9808?
All users of The Events Calendar plugin for WordPress up to and including version 6.15.2 are affected by CVE-2025-9808.
4
What type of information can be exposed by CVE-2025-9808?
CVE-2025-9808 can allow attackers to extract information about password-protected vendors or venues.
5
Is authentication required to exploit CVE-2025-9808?
No, CVE-2025-9808 can be exploited by unauthenticated attackers.