WordPress 插件 “Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)” 在所有 4.1.22 及之前的版本中,存在本地文件包含(Local File Inclusion, LFI)漏洞。该漏洞可通过 参数触发。拥有“custom”级别及以上权限的已认证攻击者,可以包含并执行服务器上的任意 文件,从而在这些文件中执行任意 PHP 代码。该漏洞可被利用来绕过访问控制、获取敏感数据,或在允许上传并包含 文件的情
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| arraytics | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce | 0 ~ 4.1.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15667 | 7.5 HIGH | Eventin <= 4.1.22 - Authenticated (Contirbutor+) Local File Inclusion via 'event_layout' P |
| CVE-2026-12956 | 5.3 MEDIUM | Eventin <= 4.1.22 - Missing Authorization to Unauthenticated Arbitrary Order Creation and |
No comments yet