Executive brief
The Event Koi Lite plugin for WordPress, used for managing event calendars and RSVPs, contains a security flaw that exposes private event information. An unauthorized person can access sensitive details such as virtual meeting links, physical locations, and RSVP settings for events that are still in draft or marked as private. This could lead to the disclosure of confidential meeting details or internal planning data before it is intended for public release.
Technical details
The Event Koi Lite plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 1.3.13.1 due to missing authorization checks in the get_events function. This vulnerability (CWE-862) allows unauthenticated attackers to query the plugin's API to retrieve metadata for events that are not publicly published. Exposed data includes virtual meeting URLs, physical location data, latitude/longitude coordinates, Google Maps links, and RSVP configurations for draft, pending, and private events. A patch has been released to address this issue in subsequent versions.
Affected products
- eventkoi Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets up to, and including, 1.3.13.1
Timeline
- 2026-06-18: disclosed
- 2026-06-18: advisory
References
- https://plugins.trac.wordpress.org/browser/eventkoi-lite/tags/1.3.0.3/includes/api/class-event.php
- https://plugins.trac.wordpress.org/browser/eventkoi-lite/tags/1.3.0.3/includes/api/class-event.php
- https://plugins.trac.wordpress.org/browser/eventkoi-lite/tags/1.3.0.3/includes/api/class-events.php
- https://plugins.trac.wordpress.org/browser/eventkoi-lite/tags/1.3.0.3/includes/api/class-events.php
- https://plugins.trac.wordpress.org/browser/eventkoi-lite/tags/1.3.0.3/includes/core/class-events.php
- https://plugins.trac.wordpress.org/browser/eventkoi-lite/tags/1.3.12.2/includes/api/class-event.php
- https://plugins.trac.wordpress.org/browser/eventkoi-lite/tags/1.3.12.2/includes/api/class-event.php