CVE-2025-39483: WordPress Eventer plugin < 3.9.9.1 - Content Injection vulnerability
Improper Control of Generation of Code ('Code Injection') vulnerability in imithemes Eventer allows Code Injection.This issue affects Eventer: from n/a before 3.9.9.1.
Other sources
Improper Control of Generation of Code ('Code Injection') vulnerability in imithemes Eventer eventer allows Code Injection.This issue affects Eventer: from n/a through < 3.9.9.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39483?
CVE-2025-39483 is classified as a high-severity vulnerability due to the risk of code injection.
How do I fix CVE-2025-39483?
To fix CVE-2025-39483, update the Imithemes Eventer plugin to version 3.9.7 or later.
What systems are affected by CVE-2025-39483?
CVE-2025-39483 affects Imithemes Eventer versions up to and including 3.9.6.
What type of vulnerability is CVE-2025-39483?
CVE-2025-39483 is a code injection vulnerability that allows an attacker to execute arbitrary code.
Can CVE-2025-39483 be exploited remotely?
Yes, CVE-2025-39483 can be exploited remotely by an attacker to inject malicious code into the application.