CVE-2025-39584: WordPress Eventin plugin <= 4.0.25 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Arraytics Eventin wp-event-solution allows PHP Local File Inclusion.This issue affects Eventin: from n/a through <= 4.0.25.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39584?
CVE-2025-39584 is classified as a high severity vulnerability due to its potential for local file inclusion, which can lead to sensitive data exposure.
How do I fix CVE-2025-39584?
To fix CVE-2025-39584, you should upgrade Themewinter Eventin to version 4.0.26 or later, which contains the necessary security patches.
What types of systems are affected by CVE-2025-39584?
CVE-2025-39584 affects Themewinter Eventin versions up to 4.0.25 on WordPress installations.
What is the impact of exploiting CVE-2025-39584?
Exploiting CVE-2025-39584 can allow attackers to include local files, potentially leading to unauthorized access to website files and data.
Is there a workaround for CVE-2025-39584?
As a temporary measure for CVE-2025-39584, you can disable the affected functionalities while a patch or upgrade is not yet implemented.