CVE-2025-26964: WordPress Eventin plugin <= 4.0.20 - Local File Inclusion vulnerability
Published Feb 25, 2025
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Arraytics Eventin wp-event-solution allows PHP Local File Inclusion.This issue affects Eventin: from n/a through <= 4.0.20.
Affected Software
3 affected components
Themewinter Eventin<=4.0.20
WordPress Eventin plugin<=4.0.20
Themewinter Eventin Wordpress<4.0.21
Remediation
Information
Update the WordPress Eventin wordpress plugin to the latest available version (at least 4.0.21).
Event History
Feb 25, 2025
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-26964?
CVE-2025-26964 is classified as a medium severity vulnerability due to its potential for local file inclusion attacks.
2
How do I fix CVE-2025-26964?
To fix CVE-2025-26964, you should update the Eventin plugin to version 4.0.21 or later.
3
What type of vulnerability is CVE-2025-26964?
CVE-2025-26964 is an improper control of filename vulnerability that can lead to PHP local file inclusion.
4
Which versions of Themewinter Eventin are affected by CVE-2025-26964?
CVE-2025-26964 affects Themewinter Eventin versions up to and including 4.0.20.
5
Can CVE-2025-26964 affect WordPress installations?
Yes, CVE-2025-26964 can affect WordPress installations that use the Eventin plugin up to version 4.0.20.