Unrestricted Upload of File with Dangerous Type vulnerability in Ovatheme Ovatheme Events Manager allows Using Malicious Files.This issue affects Ovatheme Events Manager: from n/a through 1.8.4.
Fixes

Solution

Update the WordPress Ovatheme Events Manager wordpress plugin to the latest available version (at least 1.8.5).


Workaround

No workaround given by the vendor.

History

Wed, 30 Jul 2025 06:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Jul 2025 05:45:00 +0000

Type Values Removed Values Added
Description Unrestricted Upload of File with Dangerous Type vulnerability in ovatheme Ovatheme Events Manager allows Using Malicious Files. This issue affects Ovatheme Events Manager: from n/a through 1.7.5. Unrestricted Upload of File with Dangerous Type vulnerability in Ovatheme Ovatheme Events Manager allows Using Malicious Files.This issue affects Ovatheme Events Manager: from n/a through 1.8.4.
Title WordPress Ovatheme Events Manager plugin <= 1.7.5 - Arbitrary File Upload vulnerability WordPress Ovatheme Events Manager plugin <= 1.8.4 - Arbitrary File Upload vulnerability

Tue, 17 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Description Unrestricted Upload of File with Dangerous Type vulnerability in ovatheme Ovatheme Events Manager allows Using Malicious Files. This issue affects Ovatheme Events Manager: from n/a through 1.7.5.
Title WordPress Ovatheme Events Manager plugin <= 1.7.5 - Arbitrary File Upload vulnerability
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2025-07-30T05:23:57.388Z

Reserved: 2025-04-09T11:19:28.417Z

Link: CVE-2025-32510

cve-icon Vulnrichment

Updated: 2025-06-17T18:34:48.670Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-17T15:15:42.093

Modified: 2025-07-30T06:15:26.470

Link: CVE-2025-32510

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-06-27T14:10:58Z