CVE-2025-3419: Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.26 - Unauthenticated Arbitrary File Read
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 4.0.26 via the proxyimage() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. CVE-2025-47445 is a duplicate of this vulnerability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3419?
CVE-2025-3419 is considered a high severity vulnerability as it allows unauthenticated attackers to read sensitive files on the server.
How do I fix CVE-2025-3419?
To fix CVE-2025-3419, upgrade the Event Manager, Events Calendar, Tickets, Registrations plugin to version 4.0.27 or higher.
What versions are affected by CVE-2025-3419?
CVE-2025-3419 affects all versions of the Event Manager, Events Calendar, Tickets, Registrations plugin up to and including version 4.0.26.
Can CVE-2025-3419 be exploited remotely?
Yes, CVE-2025-3419 can be exploited remotely by unauthenticated attackers.
What functionality does the CVE-2025-3419 vulnerability impact?
CVE-2025-3419 impacts the proxy_image() function, allowing attackers to access arbitrary files.