Sensitive Information Exposure in Event Koi Lite for WordPress
CVE-2026-10029

5.3MEDIUM

What is CVE-2026-10029?

The Event Koi Lite plugin for WordPress has a vulnerability that exposes sensitive information through the get_events function. This flaw allows unauthenticated users to retrieve confidential details, including virtual meeting URLs, physical locations, latitude and longitude coordinates, Google Maps links, and RSVP configurations for draft, pending, and private events. Such information, which should be secured from public access, can lead to data leaks and unauthorized disclosures, highlighting the need for prompt updates to safeguard user data.

Affected Version(s)

Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets 0 <= 1.3.13.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Umut Can Yurdayardım
.