7.5
CVE-2025-3419
- EPSS 0.19%
- Veröffentlicht 08.05.2025 05:22:51
- Zuletzt bearbeitet 04.06.2025 22:42:06
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.26 - Unauthenticated Arbitrary File Read
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 4.0.26 via the proxy_image() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Mögliche Gegenmaßnahme
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered): Update to version 4.0.27, or a newer patched version
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered)
Version
*-4.0.26
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Themewinter ≫ Eventin SwPlatformwordpress Version < 4.0.27
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.411 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| security@wordfence.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-73 External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.