Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themifyme Themify Event Post themify-event-post allows PHP Local File Inclusion.This issue affects Themify Event Post: from n/a through <= 1.3.2.
Published: 2025-03-27
Score: 7.5 High
EPSS: 1.9% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from improper validation of filename parameters in a PHP include/require statement within the Themify Event Post plugin. The flaw permits the inclusion of any local file on the web server, which can expose sensitive configuration files or, if a PHP file is included, execute arbitrary code. The weakness corresponds to CWE‑98 and is classified as a local file inclusion that could lead to remote code execution if exploited.

Affected Systems

WordPress installations that use the Themify Event Post plugin version 1.3.2 or older are affected. The vulnerability applies to all affected plugin instances regardless of site role or configuration, meaning any user capable of influencing plugin input could trigger the flaw.

Risk and Exploitability

The CVSS score of 7.5 indicates a medium to high severity. While the EPSS score of <1% shows a very low probability of exploitation at present, the flaw is not listed in the CISA KEV catalog. The likely attack vector involves external requests to the plugin that manipulate the filename parameter; a remote attacker could supply a path that points to sensitive files or to PHP scripts for code execution. Due to the nature of local file inclusion, impact can range from information disclosure to full server compromise, making timely remediation a priority.

Generated by OpenCVE AI on May 1, 2026 at 03:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Themify Event Post plugin to the latest available version that addresses the LFI flaw
  • If an update is not immediately possible, temporarily disable or delete the plugin until a patch is available
  • Enforce strict file‑permission settings on the web root so that only the necessary files are readable by the web server and prevent execution of arbitrary local files

Generated by OpenCVE AI on May 1, 2026 at 03:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8347 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themifyme Themify Event Post allows PHP Local File Inclusion. This issue affects Themify Event Post: from n/a through 1.3.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themifyme Themify Event Post allows PHP Local File Inclusion. This issue affects Themify Event Post: from n/a through 1.3.2. Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themifyme Themify Event Post themify-event-post allows PHP Local File Inclusion.This issue affects Themify Event Post: from n/a through <= 1.3.2.
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 27 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 11:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themifyme Themify Event Post allows PHP Local File Inclusion. This issue affects Themify Event Post: from n/a through 1.3.2.
Title WordPress Themify Event Post Plugin <= 1.3.2 - Local File Inclusion vulnerability
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:58.294Z

Reserved: 2025-03-26T09:20:39.457Z

Link: CVE-2025-30831

cve-icon Vulnrichment

Updated: 2025-03-27T13:58:57.447Z

cve-icon NVD

Status : Deferred

Published: 2025-03-27T11:15:44.520

Modified: 2026-04-23T15:27:09.340

Link: CVE-2025-30831

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T04:00:06Z

Weaknesses
  • CWE-98

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')