Description
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The etn_manage_event capability is assigned to Contributors by default, meaning any Contributor-level user can set the malicious event_layout value via the REST API without any additional configuration.
Published: 2026-09-09
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Eventin – Event Calendar, Tickets & Booking plugin for WordPress is vulnerable to Local File Inclusion via the 'event_layout' parameter in all versions up to 4.1.22. Authenticated users with contributor-level access and above can supply arbitrary file names; the plugin includes these files and executes their PHP code. This flaw permits bypassing access controls, retrieving sensitive data, and arbitrary code execution on the server. The weakness is a classic Local File Inclusion, classified as CWE‑98.

Affected Systems

WordPress sites using the arraytics Eventin plugin versions 4.1.22 and earlier are affected. The vendor is arraytics, and the product is Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce. No specific sub‑versions are listed beyond the upper bound of 4.1.22.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.5, indicating high severity. The EPSS score is not available, and the issue is not currently listed in CISA’s KEV catalog, which suggests that it has not yet been widely exploited. The attack requires an authenticated user with contributor or higher privilege, and the attacker must be able to reach the REST API endpoint to set the malicious 'event_layout' parameter. Once an attacker supplies a PHP file path, the plugin will include and execute the file, providing full remote code execution on the web server.

Generated by OpenCVE AI on September 9, 2026 at 04:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Eventin plugin to v4.1.23 or later to remove the LFI flaw.
  • If an upgrade cannot be performed immediately, reduce or remove the etn_manage_event capability from contributor roles to prevent malicious parameter injection.
  • Disable or restrict the WordPress REST API for non-admin users, or add strict input validation to the 'event_layout' parameter to allow only safe, non-executable files.
  • Apply file‑system permissions that prevent the web server from executing arbitrary PHP files from user-supplied paths.

Generated by OpenCVE AI on September 9, 2026 at 04:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Arraytics
Arraytics eventin – Event Calendar, Event Registration, Tickets & Booking (ai Powered)
Wordpress
Wordpress wordpress
Vendors & Products Arraytics
Arraytics eventin – Event Calendar, Event Registration, Tickets & Booking (ai Powered)
Wordpress
Wordpress wordpress

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The etn_manage_event capability is assigned to Contributors by default, meaning any Contributor-level user can set the malicious event_layout value via the REST API without any additional configuration.
Title Eventin <= 4.1.22 - Authenticated (Contirbutor+) Local File Inclusion via 'event_layout' Parameter
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Arraytics Eventin – Event Calendar, Event Registration, Tickets & Booking (ai Powered)
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-09T15:01:58.232Z

Reserved: 2026-07-13T21:12:06.098Z

Link: CVE-2026-15667

cve-icon Vulnrichment

Updated: 2026-09-09T15:01:54.445Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T03:17:23.523

Modified: 2026-09-09T16:17:01.133

Link: CVE-2026-15667

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:02:44Z

Weaknesses
  • CWE-98

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')