Input validation vulnerability in Eventin – AI Powered Event Manager, Events Calendar, Booking and Tickets Plugin 4.0.37

The Eventin plugin for WordPress, which includes features like The Events Calendar, Event Booking, Registrations, and Event Tickets, has a security vulnerability. This vulnerability, known as Server-Side Request Forgery, exists in all versions up to and including 4.0.37 through the proxy_image function. This means that hackers who are not logged in can make requests to any website through the plugin, which could potentially access and change information from internal services.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.