Event Koi Lite <= 1.3.13.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via REST API Endpoints
mediumThe Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.13.1 via the get_events. This makes it possible for unauthenticated attackers to extract sensitive data including virtual meeting URLs,...
- CVSS:
- 5.3
- Affected:
- up to 1.3.13.1
- Fixed in:
- 1.3.14.0
- Disclosed:
- Jun 17, 2026