CVE-2025-69352

WordPress The Events Calendar plugin <= 6.15.12.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through <= 6.15.12.2.


We have discovered 88,163 live websites that are affected by CVE-2025-69352.

Run a Free Instant Scan




Affected Software

Product  The Events Calendar
Category Wordpress Plugins
Vulnerable Domains88,163 live websites (92% of The Events Calendar install base)
Vulnerable Versions
  • from 0 through 6.15.12.2
Vulnerable Versions Count334 versions ( 99% of all versions)



Details

  • Published - Jan 6, 2026
  • Updated - Jan 20, 2026

Credits

  • Phat RiO - BlueRock | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2025-69352
United States32,556 websites



Germany14,216 websites
France4,973 websites
GB3,991 websites
Italy3,179 websites
Netherlands2,990 websites
Canada2,664 websites
Spain2,264 websites
Switzerland1,766 websites
Denmark1,437 websites

Website Distribution by TLD

Number of websites using CVE-2025-69352
.com25,556 websites
.org17,234 websites
.de10,556 websites
.nl3,003 websites
.fr2,418 websites
.it2,352 websites
.co.uk1,746 websites
.ca1,664 websites
.net1,588 websites
.ch1,527 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-69352

Top websites that are affected by CVE-2025-69352. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.*******.org United States*,***
*****************.com United States*,***
******.com United States**,***
*****.**.uk United States**,***
*************************.de Germany**,***
*******************.nl Netherlands**,***
***************.net United States**,***
***.org South Africa**,***
****************.com United States**,***
****.net United States**,***
See full domain list

FAQ

A total of 88,163 websites have been identified as vulnerable to CVE-2025-69352, based on global website indexing conducted by WebTechSurvey.
The The Events Calendar is affected by the CVE-2025-69352 vulnerability.
The Events Calendar versions up to and including 6.15.12.2 are vulnerable to CVE-2025-69352.