WordPress 插件 “The Events Manager – Calendar, Bookings, Tickets, and more!” 存在本地文件包含漏洞(Local File Inclusion),影响所有 7.3.7.4 及更早版本。该漏洞存在于 函数中。 借助此漏洞,拥有管理员及以上权限的经认证攻击者可以包含并执行服务器上的任意 .php 文件,从而导致这些文件中的任何 PHP 代码得以执行。在允许上传和包含 .php 文件类型的情形下,攻击者可利用该漏洞绕过访问控制、获取敏感数据,或实现代码
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| netweblogic | Events Manager – Calendar, Bookings, Tickets, and more! | 0 ~ 7.3.7.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15023 | 6.5 MEDIUM | Events Manager <= 7.4.0 - Authenticated (Contributor+) SQL Injection via 'meta_key' Parame |
| CVE-2026-17089 | 6.1 MEDIUM | Events Manager <= 7.4.0.1 - Reflected Cross-Site Scripting via 'header_format' Parameter |
| CVE-2026-10627 | 5.3 MEDIUM | Events Manager <= 7.4.0 - Missing Authorization to Unauthenticated Sensitive Information D |
No comments yet