Sensitive Information Exposure in Event Koi Lite for WordPress
CVE-2026-10029
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 June 2026
What is CVE-2026-10029?
The Event Koi Lite plugin for WordPress has a vulnerability that exposes sensitive information through the get_events function. This flaw allows unauthenticated users to retrieve confidential details, including virtual meeting URLs, physical locations, latitude and longitude coordinates, Google Maps links, and RSVP configurations for draft, pending, and private events. Such information, which should be secured from public access, can lead to data leaks and unauthorized disclosures, highlighting the need for prompt updates to safeguard user data.
Affected Version(s)
Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets 0 <= 1.3.13.1