PT-2026-78888 · WordPress · Events Made Easy

·

CVE-2026-75963

·

Published

2026-08-20

·

Updated

2026-08-21

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Events Made Easy versions prior to 3.2.6
Description The Events Made Easy plugin for WordPress contains a Local File Inclusion flaw within the eme single event page template() function. Authenticated attackers with contributor-level access or higher can use the wp page template event property to include and execute arbitrary .php files on the server. This allows for the execution of PHP code, which can be used to bypass access controls or obtain sensitive data. The stored traversal payload is triggered passively when any visitor loads the affected single-event page, requiring no further interaction from the attacker after the initial submission.
Recommendations Update to a version newer than 3.2.5.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75963

Affected Products

Events Made Easy