The Events Calendar WordPress plugin <= 6.15.2 contains an information disclosure vulnerability caused by REST endpoint exposure, letting unauthenticated attackers extract data about password-protected vendors or venues, exploit requires no authentication.
id: CVE-2025-9808
info:
name: The Events Calendar <= 6.15.2 - Information Disclosure
author: ze
...