Sensitive Information Exposure in EventPrime Plugin for WordPress
CVE-2025-14507

5.3MEDIUM

What is CVE-2025-14507?

The EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress is susceptible to a vulnerability that allows unauthenticated attackers to access confidential booking information via the REST API. This exposure affects all versions up to and including 4.2.7.0, enabling malicious actors to potentially obtain sensitive data such as user names, email addresses, ticket details, payment information, and order keys, provided the API has been enabled by site administrators. A partial patch was released in version 4.2.7.0, but users are advised to upgrade to mitigate this risk.

Affected Version(s)

EventPrime – Events Calendar, Bookings and Tickets * <= 4.2.7.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Deadbee
.