Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13799 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Xylus Themes XT Event Widget for Social Events allows PHP Local File Inclusion. This issue affects XT Event Widget for Social Events: from n/a through 1.1.7. |
Solution
Update the WordPress XT Event Widget for Social Events plugin to the latest available version (at least 1.1.8).
Workaround
No workaround given by the vendor.
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 07 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Xylus Themes XT Event Widget for Social Events allows PHP Local File Inclusion. This issue affects XT Event Widget for Social Events: from n/a through 1.1.7. | |
| Title | WordPress XT Event Widget for Social Events <= 1.1.7 - Local File Inclusion Vulnerability | |
| Weaknesses | CWE-98 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-05-07T18:18:16.274Z
Reserved: 2025-05-07T09:39:46.952Z
Link: CVE-2025-47531
Updated: 2025-05-07T17:19:29.787Z
Status : Awaiting Analysis
Published: 2025-05-07T15:16:10.197
Modified: 2025-05-08T14:39:18.800
Link: CVE-2025-47531
No data.
OpenCVE Enrichment
No data.
EUVD