CVE-2025-7813: Event Manager, Events Calendar, Booking, Registrations and Tickets – Eventin <= 4.0.37 - Unauthenticated Server-Side Request Forgery
The Events Calendar, Event Booking, Registrations and Event Tickets – Eventin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.37 via the proxyimage function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7813?
CVE-2025-7813 is classified as a critical severity vulnerability due to its potential for exploitation via Server-Side Request Forgery.
How do I fix CVE-2025-7813?
To mitigate CVE-2025-7813, update the Eventin plugin for WordPress to version 4.0.38 or later immediately.
Who is affected by CVE-2025-7813?
All users of the Eventin plugin for WordPress running versions up to and including 4.0.37 are affected by CVE-2025-7813.
What type of vulnerability is CVE-2025-7813?
CVE-2025-7813 is a Server-Side Request Forgery vulnerability that allows attackers to send unauthorized requests.
Can an authenticated user exploit CVE-2025-7813?
No, CVE-2025-7813 can be exploited by unauthenticated attackers, making it a significant security concern.