Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme Ovatheme Events allows PHP Local File Inclusion. This issue affects Ovatheme Events: from n/a through 1.2.8.
Fixes

Solution

Update the WordPress Ovatheme Events plugin to the latest available version (at least 1.2.7).


Workaround

No workaround given by the vendor.

History

Thu, 28 Aug 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 28 Aug 2025 13:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme Ovatheme Events allows PHP Local File Inclusion. This issue affects Ovatheme Events: from n/a through 1.2.8.
Title WordPress Ovatheme Events Plugin <= 1.2.8 - Local File Inclusion Vulnerability
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2025-08-28T18:36:29.222Z

Reserved: 2025-07-03T14:51:06.794Z

Link: CVE-2025-53576

cve-icon Vulnrichment

Updated: 2025-08-28T18:36:17.210Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-28T13:16:04.770

Modified: 2025-08-29T16:24:29.730

Link: CVE-2025-53576

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.