Information Exposure Vulnerability in EventON Lite Plugin for WordPress
CVE-2025-8091

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 August 2025

What is CVE-2025-8091?

The EventON Lite plugin for WordPress has a significant vulnerability that permits unauthorized users to access sensitive data from private, draft, or password-protected posts. This issue arises from inadequate restrictions associated with the add_single_eventon and add_eventon shortcodes, allowing unauthenticated attackers to exploit exposed data. Users of versions less than or equal to 2.4.6 are at risk, underscoring the need for prompt updates to safeguard sensitive information.

Affected Version(s)

EventON – Events Calendar * <= 2.4.6

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Takihana Shota
.
CVE-2025-8091 : Information Exposure Vulnerability in EventON Lite Plugin for WordPress