PT-2026-78888 · WordPress · Events Made Easy
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Events Made Easy versions prior to 3.2.6
Description
The Events Made Easy plugin for WordPress contains a Local File Inclusion flaw within the
eme single event page template() function. Authenticated attackers with contributor-level access or higher can use the wp page template event property to include and execute arbitrary .php files on the server. This allows for the execution of PHP code, which can be used to bypass access controls or obtain sensitive data. The stored traversal payload is triggered passively when any visitor loads the affected single-event page, requiring no further interaction from the attacker after the initial submission.Recommendations
Update to a version newer than 3.2.5.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Events Made Easy