Sensitive Information Exposure in EventPrime Plugin for WordPress
CVE-2025-14507
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 January 2026
What is CVE-2025-14507?
The EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress is susceptible to a vulnerability that allows unauthenticated attackers to access confidential booking information via the REST API. This exposure affects all versions up to and including 4.2.7.0, enabling malicious actors to potentially obtain sensitive data such as user names, email addresses, ticket details, payment information, and order keys, provided the API has been enabled by site administrators. A partial patch was released in version 4.2.7.0, but users are advised to upgrade to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EventPrime β Events Calendar, Bookings and Tickets * <= 4.2.7.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved