Information Exposure Vulnerability in EventON Lite Plugin for WordPress
CVE-2025-8091
4.3MEDIUM
What is CVE-2025-8091?
The EventON Lite plugin for WordPress has a significant vulnerability that permits unauthorized users to access sensitive data from private, draft, or password-protected posts. This issue arises from inadequate restrictions associated with the add_single_eventon and add_eventon shortcodes, allowing unauthenticated attackers to exploit exposed data. Users of versions less than or equal to 2.4.6 are at risk, underscoring the need for prompt updates to safeguard sensitive information.
Affected Version(s)
EventON – Events Calendar * <= 2.4.6