First published: Tue Feb 25 2025(Updated: )
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themewinter Eventin allows PHP Local File Inclusion. This issue affects Eventin: from n/a through 4.0.20.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Eventin | <=4.0.20 | |
Eventin | <=4.0.20 |
Update the WordPress Eventin wordpress plugin to the latest available version (at least 4.0.21).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26964 is classified as a medium severity vulnerability due to its potential for local file inclusion attacks.
To fix CVE-2025-26964, you should update the Eventin plugin to version 4.0.21 or later.
CVE-2025-26964 is an improper control of filename vulnerability that can lead to PHP local file inclusion.
CVE-2025-26964 affects Themewinter Eventin versions up to and including 4.0.20.
Yes, CVE-2025-26964 can affect WordPress installations that use the Eventin plugin up to version 4.0.20.