Impact
The Eventin plugin for WordPress is vulnerable to a Local File Inclusion flaw through the 'event_layout' parameter on all releases up to and including 4.1.22. An attacker who is authenticated with a custom-level role or higher can provide a file path that points to an arbitrary .php file on the server, which the plugin will include and execute as code. This allows the attacker to bypass existing access controls, read or modify sensitive data, and ultimately run arbitrary PHP code within the context of the WordPress site.
Affected Systems
The affected product is the Eventin – Event Calendar, Tickets, Registration, and Booking plugin from arraytics. Any installation of Eventin versions 4.1.22 or earlier is vulnerable, regardless of the overall WordPress version. The plugin is available from the WordPress plugin repository and is used by sites that require event scheduling features.
Risk and Exploitability
The CVSS score of 7.5 classifies the vulnerability as high severity, while the EPSS score is not available so the current exploitation likelihood cannot be defined numerically. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker have at least custom-level access to the WordPress admin dashboard, which allows them to submit the malicious 'event_layout' value. If a .php file can be uploaded or already exists on the server, the attacker can achieve full code execution. In the absence of a patch, the risk is moderate to high for any site that allows such role permissions and has writable directories where PHP files can reside.
OpenCVE Enrichment