CVE-2025-12175
EUVD-2025-3731431.10.2025, 09:15
The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'tec_qr_code_modal' AJAX endpoint in all versions up to, and including, 6.15.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view draft event names and generate/view QR codes for them.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| stellarwp | the_events_calendar | 𝑥 ≤ 6.15.9 | CNA |
Common Weakness Enumeration
References