PT-2026-81164 · WordPress · Events Manager
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Events Manager – Calendar, Bookings, Tickets, and more! versions prior to 7.3.7.5
Description
An issue exists in the
em options save() function that allows authenticated attackers with administrator-level access to perform Local File Inclusion. This occurs when a malicious traversal key is stored and subsequently executed via an include once() call during every admin init invocation, including unauthenticated admin-ajax.php requests. This can lead to the execution of arbitrary PHP code if .php files can be uploaded, enabling attackers to bypass access controls or obtain sensitive data.Recommendations
Update to version 7.3.7.5 or later.
As a temporary mitigation, restrict administrator-level access to the
em options save() function.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Events Manager