Event Manager, Events Calendar, Tickets, Registrations – Eventin Arbitrary File Read Vulnerability
Vulnerability
A vulnerability allowing arbitrary file read has been identified in the Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress, affecting all versions through 4.0.26. The issue arises in the proxy_image() function, where unauthenticated attackers can read the contents of arbitrary files on the server, potentially exposing sensitive information.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive files on the server.
Remediation
Users are advised to update the plugin to version 4.0.27 or a newer patched version.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
8.1remediation
7.7relevance
0.0threat
3.2urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
