The Pretty Google Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the pgcal_ajax_handler() function in all versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to retrieve the Google API key set in the plugin's settings.
Metrics
Affected Vendors & Products
References
History
Sat, 20 Dec 2025 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Pretty Google Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the pgcal_ajax_handler() function in all versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to retrieve the Google API key set in the plugin's settings. | |
| Title | Pretty Google Calendar <= 2.0.0 - Missing Authorization to Unauthenticated Google API Key Exposure | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-12-20T03:20:22.435Z
Reserved: 2025-11-07T19:05:37.066Z
Link: CVE-2025-12898
No data.
Status : Received
Published: 2025-12-20T04:16:07.043
Modified: 2025-12-20T04:16:07.043
Link: CVE-2025-12898
No data.
OpenCVE Enrichment
No data.