CVE-2026-22394: WordPress Evently theme <= 1.7 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Evently evently allows PHP Local File Inclusion.This issue affects Evently: from n/a through <= 1.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22394?
CVE-2026-22394 is considered a critical vulnerability as it allows local file inclusion which can lead to remote code execution.
How do I fix CVE-2026-22394?
To fix CVE-2026-22394, update the Mikado-Themes Evently theme to version 1.8 or later.
What are the risks associated with CVE-2026-22394?
The risks associated with CVE-2026-22394 include unauthorized access to server files and potential exploitation by attackers.
Who is affected by CVE-2026-22394?
CVE-2026-22394 affects users running Mikado-Themes Evently version 1.7 or earlier.
Is there a workaround for CVE-2026-22394?
A temporary workaround for CVE-2026-22394 may include disabling the affected theme until an update can be applied.