Unauthenticated Disclosure of NASA Organizer Email Addresses via The Events Calendar REST API (CVE-2025-9808)

Disclosed by
ARTanvir76
Summary by National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program

There is no sensitive data available.

Summary by ARTanvir76

An unauthenticated information disclosure vulnerability exists in the The Events Calendar WordPress plugin (≤ 6.15.2) due to exposed REST API endpoints. An attacker can access organizer-related data, including email addresses and contact information, without authentication. This issue corresponds to CVE-2025-9808 and affects a NASA subdomain, increasing the risk of targeted phishing and social engineering attacks.

Activity