CVE · High

CVE-2025-49869 — Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.32

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-49869 Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.32 Deserialization of Untrusted Data High 8.8 < 4.0.32 4.0.32 2025-08-13

CVE-2025-49869

The Eventin WordPress plugin contains a vulnerability that allows attackers with contributor-level access and above to inject malicious PHP objects through untrusted input deserialization in versions up to 4.0.31. This flaw can be exploited by an attacker who has the necessary permissions to introduce arbitrary data into the system, potentially leading to severe consequences such as file deletion or sensitive information retrieval.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.