CVE · Medium

CVE-2024-56213 — Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-56213 Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.9 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 6.5 < 4.0.9 4.0.9 2024-12-19

CVE-2024-56213

The Eventin event management plugin for WordPress contains a local file inclusion vulnerability affecting versions through 4.0.7 that allows authenticated users with contributor permissions or higher to include and execute arbitrary files from the server. An attacker exploiting this flaw could run PHP code from uploaded files, potentially circumventing authorization restrictions, accessing confidential information, or executing malicious code when supposedly safe file types like images are uploaded and then included.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.