Impact
The Eventin WordPress plugin, before version 4.1.20, fails to validate the path supplied for the speaker_template setting, allowing users with editor-level or higher privileges to supply any filesystem path and cause the plugin to include the selected file as PHP code. This flaw gives an attacker who can edit the speaker_template value the ability to include and execute arbitrary local files, resulting in potential remote code execution on the hosting server.
Affected Systems
All WordPress installations that use the Eventin plugin before version 4.1.20 are potentially affected. The plugin vendor is listed only as Eventin; no specific vendor or product hierarchy is provided beyond that name.
Risk and Exploitability
Because the flaw requires authenticated access with at least editor privileges, an attacker must compromise such an account or obtain credentials through other means. Once the attacker can modify the speaker_template setting, the inclusion of arbitrary local files can be triggered via ordinary browsing of the affected site, leading to code execution. The EPSS score of < 1% indicates a low current probability of exploitation, and the vulnerability is not listed in CISA KEV, suggesting limited public exploitation. Nevertheless, the potential for remote code execution remains significant, especially in shared hosting environments. The CVSS score of 7.2 reflects a high severity.
OpenCVE Enrichment