CVE-2025-30895: WordPress WpEvently Plugin <= 4.2.9 - PHP Object Injection vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in magepeopleteam WpEvently mage-eventpress allows PHP Local File Inclusion.This issue affects WpEvently: from n/a through <= 4.2.9.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30895?
CVE-2025-30895 is considered a critical vulnerability due to its potential for PHP Local File Inclusion and exploitation.
How do I fix CVE-2025-30895?
To fix CVE-2025-30895, upgrade the WpEvently plugin to version 4.2.10 or later, where the vulnerability is addressed.
What versions of WpEvently are affected by CVE-2025-30895?
CVE-2025-30895 affects WpEvently versions from n/a up to and including 4.2.9.
What type of vulnerability is CVE-2025-30895?
CVE-2025-30895 is classified as a Path Traversal vulnerability that allows for improper limitation of a pathname.
Can CVE-2025-30895 lead to remote code execution?
Yes, the PHP Local File Inclusion associated with CVE-2025-30895 can potentially lead to remote code execution.