Information Disclosure Vulnerability in The Events Calendar Plugin by Modern Tribe
CVE-2025-12192
5.3MEDIUM
What is CVE-2025-12192?
The Events Calendar plugin for WordPress contains a vulnerability that allows unauthenticated attackers to gain sensitive system information. This occurs because the sysinfo REST endpoint utilizes a loose comparison for the provided key against the stored opt-in key. If the setting to automatically share system information is enabled, attackers can exploit this flaw by submitting a boolean value, thus retrieving the entire system report. This results in significant security risks, particularly for users who have enabled this feature.
Affected Version(s)
The Events Calendar * <= 6.15.9