CVE-2026-84898: Eventin < 4.1.21 - Contributor+ LFI via Event Layout Meta
Published Sep 5, 2026
·Updated
The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with contributor-level access and above to include and execute arbitrary local PHP files.
Affected Software
1 affected component
wordpress/plugin/eventin<4.1.21
Event History
Sep 5, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs a WordPress account with at least Contributor-level access. Unauthenticated visitors are not described as able to exploit it.
2
What is the impact of successful exploitation?
A qualifying authenticated user can cause the plugin to include and execute arbitrary local PHP files by supplying a crafted template path value.
3
Which versions need remediation?
Eventin versions before 4.1.21 are affected. Updating to version 4.1.21 or later addresses the affected version range described.