CVE-2025-49869: WordPress Eventin Plugin <= 4.0.31 - PHP Object Injection Vulnerability
Deserialization of Untrusted Data vulnerability in Arraytics Eventin allows Object Injection. This issue affects Eventin: from n/a through 4.0.31.
Other sources
Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a through <= 4.0.31.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49869?
CVE-2025-49869 is categorized as a high severity vulnerability due to its potential for object injection leading to remote code execution.
How do I fix CVE-2025-49869?
The recommended fix for CVE-2025-49869 is to update the Arraytics Eventin and WordPress Eventin Plugin to the latest version beyond 4.0.31.
What does CVE-2025-49869 affect?
CVE-2025-49869 affects the Arraytics Eventin software and the WordPress Eventin Plugin up to version 4.0.31.
What type of vulnerability is CVE-2025-49869?
CVE-2025-49869 is a deserialization of untrusted data vulnerability that allows for object injection.
Can CVE-2025-49869 be exploited remotely?
Yes, CVE-2025-49869 can be exploited remotely, potentially allowing an attacker to execute arbitrary code.