Vulnerability Description
The Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.13.1 via the get_events. This makes it possible for unauthenticated attackers to extract sensitive data including virtual meeting URLs, physical location data, latitude/longitude coordinates, Google Maps links, and RSVP configuration belonging to draft, pending, and private events that are otherwise inaccessible via public URLs.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/eventkoi-lite/tags/1.3.0.3/includes/a
- https://plugins.trac.wordpress.org/browser/eventkoi-lite/tags/1.3.0.3/includes/a
- https://plugins.trac.wordpress.org/browser/eventkoi-lite/tags/1.3.0.3/includes/a
- https://plugins.trac.wordpress.org/browser/eventkoi-lite/tags/1.3.0.3/includes/a
- https://plugins.trac.wordpress.org/browser/eventkoi-lite/tags/1.3.0.3/includes/c
- https://plugins.trac.wordpress.org/browser/eventkoi-lite/tags/1.3.12.2/includes/
- https://plugins.trac.wordpress.org/browser/eventkoi-lite/tags/1.3.12.2/includes/
- https://plugins.trac.wordpress.org/browser/eventkoi-lite/tags/1.3.12.2/includes/
- https://plugins.trac.wordpress.org/browser/eventkoi-lite/tags/1.3.12.2/includes/
- https://plugins.trac.wordpress.org/browser/eventkoi-lite/tags/1.3.12.2/includes/
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old
- https://www.wordfence.com/threat-intel/vulnerabilities/id/b1be4b6c-ce48-49a2-8d2
FAQ
What is CVE-2026-10029?
CVE-2026-10029 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.13.1 via the ge...
How severe is CVE-2026-10029?
CVE-2026-10029 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-10029?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.