---
id: CVE-2025-12408
title: >-
  The Events Manager – Calendar, Bookings, Tickets, and more! plugin for
  WordPress is vulnerable to Information Exposure in all versions up to, and
  including, 7.2.2.2 via the 'get_location' action due to insufficient
  restrictions on which …
summary: >-
  The Events Manager – Calendar, Bookings, Tickets, and more! plugin for
  WordPress is vulnerable to Information Exposure in all versions up to, and
  including, 7.2.2.2 via the 'get_location' action due to insufficient
  restrictions on which …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
published: '2025-12-12'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12408'
references:
  - url: >-
      https://plugins.trac.wordpress.org/changeset/3392395/events-manager/trunk/em-actions.php
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/8470b7be-6fae-4941-b523-93e230366522?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00332
epssPercentile: 0.24232
ingestedAt: '2026-10-07T20:46:46.901Z'
---

## Overview

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 7.2.2.2 via the 'get_location' action due to insufficient restrictions on which locations can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft event locations that they should not have access to.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
