The Events Calendar WordPress Plugin Information Disclosure Vulnerability

Vulnerability

A vulnerability allowing information disclosure has been identified in The Events Calendar plugin for WordPress, affecting versions through 6.15.9. The issue arises in the sysinfo REST endpoint, where a loose comparison is used to validate the opt-in key. This flaw enables unauthenticated attackers to send a boolean value and retrieve the complete system report, but only if the user has opted to share system information with The Events Calendar support team.

Impact

Exploitation of this vulnerability allows unauthenticated attackers to access sensitive system information from the WordPress site.

Remediation

Users can update to version 6.15.10 or a newer patched version to address this vulnerability.

Added: Nov 5, 2025, 10:22 AM
Updated: Nov 5, 2025, 10:22 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
2.5
exploitability
8.2
remediation
7.7
relevance
0.9
threat
3.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.