Impact
A content injection flaw in the Eventer WordPress plugin enables attackers to inject arbitrary code, potentially resulting in remote code execution if the plugin processes user‑supplied content. The issue stems from improper control over code generation, classified as a Code Injection (CWE‑94) weakness. If exploited, attackers could execute malicious scripts within the WordPress environment, compromising confidentiality, integrity, and availability of the site.
Affected Systems
The vulnerability affects the Eventer plugin from imithemes, specifically all releases younger than 3.9.9.1. Users running any Eventer version below 3.9.9.1 on a WordPress site are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests a low exploitation probability at present, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is through the plugin's shortcode or widget interface accessible to Site administrators or potentially to regular users if the plugin is exposed, making it a local or privilege‑escalation attack within the WordPress context.
OpenCVE Enrichment
EUVD