CVE-2024-7149: Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.8 - Authenticated (Contributor+) Local File Inclusion
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.8 via multiple style parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7149?
The severity of CVE-2024-7149 is classified as critical due to the potential for local file inclusion.
How do I fix CVE-2024-7149?
To fix CVE-2024-7149, update the Eventin plugin for WordPress to version 4.0.9 or later.
Who is affected by CVE-2024-7149?
Authenticated users with Contributor-level access are affected by CVE-2024-7149.
What is local file inclusion in the context of CVE-2024-7149?
Local file inclusion in CVE-2024-7149 allows attackers to include files on the server through manipulated style parameters.
Which versions of the Eventin plugin are vulnerable to CVE-2024-7149?
All versions of the Eventin plugin for WordPress up to and including 4.0.8 are vulnerable to CVE-2024-7149.