Impact
The Ovatheme Events Manager WordPress plugin allows unauthenticated users to upload any file because the process_checkout() function fails to validate the file type. An attacker can place malicious code on the server, potentially enabling remote code execution. This flaw is classified as CWE-434.
Affected Systems
The vulnerability affects all installations of the Ovatheme Events Manager WordPress plugin up to and including version 1.8.5. Sites running that version or older are vulnerable.
Risk and Exploitability
With a CVSS score of 9.8, the flaw is considered critical. The EPSS score is below 1%, indicating a very low expected exploitation rate, and it is not currently listed in the CISA KEV catalog. Attackers can exploit the flaw by sending a crafted file through the exposed process_checkout endpoint without authentication.
OpenCVE Enrichment