
Disclosure for CVE-2025-8091
Disclosure for CVE-2025-8091
This repository discloses a vulnerability discovered in EventON Lite <= 2.4.6,WordPress plugin developed by Ashan Perera.
| CVE ID | Type | Component | Impact |
|---|---|---|---|
| CVE-2025-8091 | Exposure of Sensitive Information to an Unauthorized Actor | class-calendar-generator.php | Authenticated (Contributor+) Information Disclosure |
[add_single_eventon id="xxxx"]The post_type parameter is not properly validated, allowing retrieval of unintended post types including private or draft events.
post_type before executing the query.current_user_can('read_private_ajde_events') for private content.post_status to publish for users without the necessary privileges.人生初のCVE 寄稿者から攻撃可能であるため脅威度はかなり低い。StatusをAnyからPublicに変更するだけなので、脆弱性を治すのはとても簡単そう。
Name: MooseLove
Role: Independent security researcher / bug hunter
Contact: Available upon request
This advisory is provided for public security awareness. Free to share with attribution.