
CVE-2025-47539 – WordPress Eventin <= 4.0.26 - Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2025-47539
07 May 2025 — Incorrect Privilege Assignment vulnerability in Themewinter Eventin allows Privilege Escalation. This issue affects Eventin: from n/a through 4.0.26. The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the import_items() function in all versions up to, and including, 4.0.26. This makes it possible for unauthenticated attackers to import users that can have the administrator role leading to privile... • https://packetstorm.news/files/id/193132 • CWE-266: Incorrect Privilege Assignment CWE-862: Missing Authorization •

CVE-2025-39584 – WordPress Eventin <= 4.0.25 - Local File Inclusion Vulnerability
https://notcve.org/view.php?id=CVE-2025-39584
16 Apr 2025 — Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themewinter Eventin allows PHP Local File Inclusion. This issue affects Eventin: from n/a through 4.0.25. The Eventin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.25 via the 'events_tab' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the se... • https://patchstack.com/database/wordpress/plugin/wp-event-solution/vulnerability/wordpress-eventin-4-0-25-local-file-inclusion-vulnerability?_s_id=cve • CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') •

CVE-2025-26964 – WordPress Eventin plugin <= 4.0.20 - Local File Inclusion vulnerability
https://notcve.org/view.php?id=CVE-2025-26964
23 Feb 2025 — Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themewinter Eventin allows PHP Local File Inclusion. This issue affects Eventin: from n/a through 4.0.20. The Eventin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.20. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of... • https://patchstack.com/database/wordpress/plugin/wp-event-solution/vulnerability/wordpress-eventin-plugin-4-0-20-local-file-inclusion-vulnerability?_s_id=cve • CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') •

CVE-2024-56213 – WordPress Eventin plugin <= 4.0.7 - Contributor+ Limited Local File Inclusion vulnerability
https://notcve.org/view.php?id=CVE-2024-56213
19 Dec 2024 — Path Traversal: '.../...//' vulnerability in Themewinter Eventin allows Path Traversal.This issue affects Eventin: from n/a through 4.0.7. Path Traversal: la vulnerabilidad '.../...//' en Themewinter Eventin permite Path Traversal. Este problema afecta a Eventin: desde n/a hasta 4.0.7. The Eventin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.7. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execu... • https://patchstack.com/database/wordpress/plugin/wp-event-solution/vulnerability/wordpress-eventin-plugin-4-0-7-contributor-limited-local-file-inclusion-vulnerability?_s_id=cve • CWE-35: Path Traversal: '.../...//' CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') •

CVE-2024-39648 – WordPress Eventin plugin <= 4.0.5 - Cross Site Scripting (XSS) vulnerability
https://notcve.org/view.php?id=CVE-2024-39648
01 Aug 2024 — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.This issue affects Eventin: from n/a through 4.0.5. The Eventin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that w... • https://patchstack.com/database/vulnerability/wp-event-solution/wordpress-eventin-plugin-4-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-37507 – WordPress Eventin plugin <= 3.3.57 - Cross Site Scripting (XSS) vulnerability
https://notcve.org/view.php?id=CVE-2024-37507
04 Jul 2024 — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.This issue affects Eventin: from n/a through 3.3.57. Vulnerabilidad de neutralización incorrecta de la entrada durante la generación de páginas web (XSS o 'Cross-site Scripting') en Themewinter Eventin permite XSS almacenado. Este problema afecta a Eventin: desde n/a hasta 3.3.57. The Eventin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve... • https://patchstack.com/database/vulnerability/wp-event-solution/wordpress-eventin-plugin-3-3-57-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-49756 – WordPress Eventin plugin <= 3.3.52 - Authenticated Notice Dismissal Vulnerability
https://notcve.org/view.php?id=CVE-2023-49756
04 Dec 2023 — Missing Authorization vulnerability in Themewinter Eventin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eventin: from n/a through 3.3.52. The Eventin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the import_file() function in versions up to, and including, 3.3.52. This makes it possible for authenticated attackers, with subscriber-level access and above, to import events. • https://patchstack.com/database/wordpress/plugin/wp-event-solution/vulnerability/wordpress-eventin-plugin-3-3-44-authenticated-notice-dismissal-vulnerability?_s_id=cve • CWE-862: Missing Authorization •