Magepeople WpEvently Plugin Path Traversal Vulnerability Leading to PHP Local File Inclusion
Vulnerability
A path traversal vulnerability allowing PHP local file inclusion has been identified in the WpEvently plugin by Magepeople, affecting versions through 4.2.9. This vulnerability arises from improper restrictions on pathname navigation, which could be exploited to include local files from the server.
Impact
Exploitation of this vulnerability could lead to unauthorized inclusion of local files, with the potential to display sensitive information such as database credentials. Depending on the server configuration, this could result in a complete takeover of the database.
Remediation
Users of the WpEvently plugin should update to version 4.3.0 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
