CVE Database /
CVE-2024-56213
CVE · Medium
CVE-2024-56213 — Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.9
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-56213
|
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.9 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Medium
6.5
|
< 4.0.9
|
4.0.9 |
2024-12-19 |
—
|
CVE-2024-56213
The Eventin event management plugin for WordPress contains a local file inclusion vulnerability affecting versions through 4.0.7 that allows authenticated users with contributor permissions or higher to include and execute arbitrary files from the server. An attacker exploiting this flaw could run PHP code from uploaded files, potentially circumventing authorization restrictions, accessing confidential information, or executing malicious code when supposedly safe file types like images are uploaded and then included.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings