Impact
The Eventin WordPress plugin, in all releases prior to 4.1.20, fails to validate the path supplied for the speaker_template setting. Users who hold editor-level or higher privileges can supply any filesystem path, causing the plugin to include the specified file as PHP code. The vulnerability therefore allows an attacker who can edit the speaker_template value to include and execute arbitrary local files, effectively achieving remote code execution on the hosting server.
Affected Systems
All WordPress installations that use the Eventin plugin before version 4.1.20 are potentially affected. The vulnerability exists across the entire plugin package, regardless of site size or configuration, as long as the speaker_template setting is exposed to an editor account. The plugin vendor is listed only as Eventin; no specific vendor or product hierarchy is provided beyond that name.
Risk and Exploitability
Because the flaw requires authenticated access with at least editor privileges, an attacker must first compromise an account with such permissions or obtain credentials through other means. Once the attacker can modify the speaker_template setting, the inclusion of arbitrary local files can be triggered via ordinary browsing of the affected site. No EPSS data is available for this issue, and it is not listed in the CISA KEV catalog, which suggests limited exploitation evidence to date. Nevertheless, the path traversal can lead to full code execution on the server and therefore poses a high severity risk, especially in multi‑tenant or shared hosting environments.
OpenCVE Enrichment