CVE-2025-47445: WordPress Eventin plugin <= 4.0.26 - Arbitrary File Download Vulnerability
Published May 14, 2025
·Updated
Relative Path Traversal vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <= 4.0.26.
Affected Software
3 affected components
Themewinter Eventin<=4.0.26
WordPress Eventin<=4.0.26
Themewinter Eventin Wordpress<4.0.27
Remediation
Information
Update the WordPress Eventin plugin to the latest available version (at least 4.0.27).
Event History
May 14, 2025
CVE Published
via MITRE·11:37 AM
Data Sourced
via MITRE·11:37 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-47445?
The severity of CVE-2025-47445 is considered high due to its potential for unauthorized file access.
2
How do I fix CVE-2025-47445?
To fix CVE-2025-47445, upgrade Themewinter Eventin to version 4.0.27 or later.
3
What versions are affected by CVE-2025-47445?
CVE-2025-47445 affects Themewinter Eventin and WordPress Eventin versions up to and including 4.0.26.
4
What is a Relative Path Traversal vulnerability like CVE-2025-47445?
A Relative Path Traversal vulnerability allows attackers to access files and directories stored outside the intended directory.
5
Can CVE-2025-47445 lead to data exposure?
Yes, CVE-2025-47445 can lead to data exposure by allowing unauthorized access to sensitive files.