Impact
The Eventin – Event Calendar, Tickets & Booking plugin for WordPress is vulnerable to Local File Inclusion via the 'event_layout' parameter in all versions up to 4.1.22. Authenticated users with contributor-level access and above can supply arbitrary file names; the plugin includes these files and executes their PHP code. This flaw permits bypassing access controls, retrieving sensitive data, and arbitrary code execution on the server. The weakness is a classic Local File Inclusion, classified as CWE‑98.
Affected Systems
WordPress sites using the arraytics Eventin plugin versions 4.1.22 and earlier are affected. The vendor is arraytics, and the product is Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce. No specific sub‑versions are listed beyond the upper bound of 4.1.22.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating high severity. The EPSS score is not available, and the issue is not currently listed in CISA’s KEV catalog, which suggests that it has not yet been widely exploited. The attack requires an authenticated user with contributor or higher privilege, and the attacker must be able to reach the REST API endpoint to set the malicious 'event_layout' parameter. Once an attacker supplies a PHP file path, the plugin will include and execute the file, providing full remote code execution on the web server.
OpenCVE Enrichment