Access violation vulnerability in Eventin – Event Manager, Events Calendar, Event Tickets and Registrations 4.0.24

The plugin called Eventin for WordPress, which includes features such as Event Manager, Events Calendar, Tickets, and Registrations, has a security issue where anyone with Contributor-level access or higher can include and run files on the server. This can be used to access restricted areas, get private information, or execute code. This vulnerability exists in all versions up to 4.0.24 and can be exploited through the ‘style’ parameter.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.