CVE-2025-32594

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 17, 2025
CWE ID 201

Summary

CVE-2025-32594 is a vulnerability affecting the WPMinds Simple WP Events plugin, where an Insertion of Sensitive Information Into Sent Data issue exists. This means that malicious actors can embed sensitive data into event data, which could then be retrieved by attackers. The vulnerability affects versions of Simple WP Events from n/a through 1.8.17. Successful exploitation of this flaw could lead to unauthorized access to sensitive information. Users are strongly urged to update to the latest version of the plugin to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share