CVE-2026-13170: Eventin < 4.1.20 - Editor+ Local File Inclusion via speaker_template Setting
The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13170?
CVE-2026-13170 has a risk rating of 50, indicating a moderate severity level.
How do I fix CVE-2026-13170?
To fix CVE-2026-13170, update the Eventin WordPress plugin to version 4.1.20 or later.
What impact does CVE-2026-13170 have on my WordPress site?
CVE-2026-13170 allows users with editor-level access to include arbitrary local PHP files, potentially compromising the security of your WordPress site.
Who is affected by CVE-2026-13170?
CVE-2026-13170 affects users of the Eventin WordPress plugin prior to version 4.1.20.
Can CVE-2026-13170 be exploited remotely?
CVE-2026-13170 requires editor-level access, making it less likely to be exploited remotely compared to vulnerabilities that can be attacked by unauthenticated users.