Themewinter Eventin vulnerabilities
16 known vulnerabilities affecting themewinter/eventin.
Total CVEs
16
CISA KEV
0
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL2HIGH8MEDIUM6
Vulnerabilities
Page 1 of 1
CVE-2025-47539P1CRITICALCVSS 9.8ExploitedPoCfixed in 4.0.272025-05-23
CVE-2025-47539 [CRITICAL] CWE-266 CVE-2025-47539: Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege
Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a through <= 4.0.26.
nvd
CVE-2025-47445P1CRITICALCVSS 9.8ExploitedPoCfixed in 4.0.272025-05-14
CVE-2025-47445 [CRITICAL] CWE-23 CVE-2025-47445: Relative Path Traversal vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.T
Relative Path Traversal vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <= 4.0.26.
nvd
CVE-2025-4796P2HIGHCVSS 8.8fixed in 4.0.352025-08-08
CVE-2025-4796 [HIGH] CWE-639 CVE-2025-4796: The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all v
The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due to the plugin not properly validating a user's identity or capability prior to updating their details like email in the 'Eventin\Speaker\Api\SpeakerController::update_item' function. This makes it possible
nvd
CVE-2025-1770P3HIGHCVSS 8.8fixed in 4.0.252025-03-20
CVE-2025-1770 [HIGH] CWE-22 CVE-2025-1770: The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnera
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.24 via the 'style' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing
nvd
CVE-2024-7149P3HIGHCVSS 8.8fixed in 4.0.92024-09-27
CVE-2024-7149 [HIGH] CWE-22 CVE-2024-7149: The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnera
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.8 via multiple style parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowi
nvd
CVE-2024-56213P3HIGHCVSS 8.8fixed in 4.0.92024-12-31
CVE-2024-56213 [HIGH] CWE-35 CVE-2024-56213: Path Traversal: '.../...//' vulnerability in Arraytics Eventin wp-event-solution allows Path Travers
Path Traversal: '.../...//' vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <= 4.0.7.
nvd
CVE-2025-26964P3HIGHCVSS 8.8fixed in 4.0.212025-02-25
CVE-2025-26964 [HIGH] CWE-98 CVE-2025-26964: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Arraytics Eventin wp-event-solution allows PHP Local File Inclusion.This issue affects Eventin: from n/a through <= 4.0.20.
nvd
CVE-2023-49756P3HIGHCVSS 8.8fixed in 3.3.532024-12-09
CVE-2023-49756 [HIGH] CWE-862 CVE-2023-49756: Missing Authorization vulnerability in Arraytics Eventin wp-event-solution allows Exploiting Incorre
Missing Authorization vulnerability in Arraytics Eventin wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eventin: from n/a through <= 3.3.52.
nvd
CVE-2025-3419P3HIGHCVSS 7.5fixed in 4.0.272025-05-08
CVE-2025-3419 [HIGH] CWE-73 CVE-2025-3419: The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnera
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 4.0.26 via the proxy_image() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. CVE
nvd
CVE-2025-39584P3HIGHCVSS 7.5fixed in 4.0.262025-04-16
CVE-2025-39584 [HIGH] CWE-98 CVE-2025-39584: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Arraytics Eventin wp-event-solution allows PHP Local File Inclusion.This issue affects Eventin: from n/a through <= 4.0.25.
nvd
CVE-2025-1766P4MEDIUMCVSS 5.3fixed in 4.0.252025-03-20
CVE-2025-1766 [MEDIUM] CWE-862 CVE-2025-1766: The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnera
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'payment_complete' function in all versions up to, and including, 4.0.24. This makes it possible for unauthenticated attackers to update the status of ticket payments to '
nvd
CVE-2024-1122P4MEDIUMCVSS 5.3fixed in 3.3.512024-02-09
CVE-2024-1122 [MEDIUM] CWE-862 CVE-2024-1122: The Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin plugin for WordPress is
The Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_data() function in all versions up to, and including, 3.3.50. This makes it possible for unauthenticated attackers to export event data.
nvd
CVE-2024-37507P4MEDIUMCVSS 5.4fixed in 4.0.0≥ n/a, ≤ 3.3.572024-07-21
CVE-2024-37507 [MEDIUM] CWE-79 CVE-2024-37507: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.This issue affects Eventin: from n/a through 3.3.57.
nvd
CVE-2025-49321P4MEDIUMCVSS 6.1fixed in 4.0.292025-06-27
CVE-2025-49321 [MEDIUM] CWE-79 CVE-2025-49321: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arraytics Eventin wp-event-solution allows Reflected XSS.This issue affects Eventin: from n/a through <= 4.0.28.
nvd
CVE-2024-6033P4MEDIUMCVSS 4.3fixed in 4.0.52024-07-17
CVE-2024-6033 [MEDIUM] CWE-862 CVE-2024-6033: The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnera
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized data importation due to a missing capability check on the 'import_file' function in all versions up to, and including, 4.0.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to import even
nvd
CVE-2024-39648P4MEDIUMCVSS 4.8fixed in 4.0.6≥ n/a, ≤ 4.0.52024-08-01
CVE-2024-39648 [MEDIUM] CWE-79 CVE-2024-39648: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.This issue affects Eventin: from n/a through 4.0.5.
nvd