Description
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with custom-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
Published: 2026-09-09
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Eventin plugin for WordPress is vulnerable to a Local File Inclusion flaw through the 'event_layout' parameter on all releases up to and including 4.1.22. An attacker who is authenticated with a custom-level role or higher can provide a file path that points to an arbitrary .php file on the server, which the plugin will include and execute as code. This allows the attacker to bypass existing access controls, read or modify sensitive data, and ultimately run arbitrary PHP code within the context of the WordPress site.

Affected Systems

The affected product is the Eventin – Event Calendar, Tickets, Registration, and Booking plugin from arraytics. Any installation of Eventin versions 4.1.22 or earlier is vulnerable, regardless of the overall WordPress version. The plugin is available from the WordPress plugin repository and is used by sites that require event scheduling features.

Risk and Exploitability

The CVSS score of 7.5 classifies the vulnerability as high severity, while the EPSS score is not available so the current exploitation likelihood cannot be defined numerically. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker have at least custom-level access to the WordPress admin dashboard, which allows them to submit the malicious 'event_layout' value. If a .php file can be uploaded or already exists on the server, the attacker can achieve full code execution. In the absence of a patch, the risk is moderate to high for any site that allows such role permissions and has writable directories where PHP files can reside.

Generated by OpenCVE AI on September 9, 2026 at 04:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Eventin plugin to the latest version that fixes the Local File Inclusion bug (any release newer than 4.1.22).
  • Revoke or downgrade custom-level user roles so that only administrators or trusted users can invoke event layout functionality, thereby limiting the attacker’s ability to supply a malicious parameter.
  • Validate and sanitize the 'event_layout' input by restricting the allowed values to a predefined set of template names, or configure the server or plugin to ignore the parameter entirely if the feature is not required.

Generated by OpenCVE AI on September 9, 2026 at 04:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Arraytics
Arraytics eventin – Event Calendar, Event Registration, Tickets & Booking (ai Powered)
Wordpress
Wordpress wordpress
Vendors & Products Arraytics
Arraytics eventin – Event Calendar, Event Registration, Tickets & Booking (ai Powered)
Wordpress
Wordpress wordpress

Sat, 12 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with custom-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
Title Eventin <= 4.1.22 - Authenticated (Custom+) Local File Inclusion via 'event_layout' Parameter
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Arraytics Eventin – Event Calendar, Event Registration, Tickets & Booking (ai Powered)
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-11T20:19:15.061Z

Reserved: 2026-07-10T13:53:01.204Z

Link: CVE-2026-15406

cve-icon Vulnrichment

Updated: 2026-09-11T20:13:50.107Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T03:17:23.157

Modified: 2026-09-11T21:17:08.367

Link: CVE-2026-15406

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:02:46Z

Weaknesses
  • CWE-98

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')