Sensitive Information Exposure in EventPrime Plugin for WordPress
CVE-2025-14507
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 January 2026
What is CVE-2025-14507?
The EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress is susceptible to a vulnerability that allows unauthenticated attackers to access confidential booking information via the REST API. This exposure affects all versions up to and including 4.2.7.0, enabling malicious actors to potentially obtain sensitive data such as user names, email addresses, ticket details, payment information, and order keys, provided the API has been enabled by site administrators. A partial patch was released in version 4.2.7.0, but users are advised to upgrade to mitigate this risk.
Affected Version(s)
EventPrime β Events Calendar, Bookings and Tickets 0 <= 4.2.7.0