WordPress 插件 “The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)” 在包括 4.1.22 及之前的所有版本中,通过 参数存在本地文件包含(LFI)漏洞。 该漏洞允许具有“贡献者(Contributor)”级别及以上权限的已认证攻击者,在服务器上包含并执行任意的 文件,从而执行这些文件中包含的任何 PHP 代码。攻击者可借此绕过访问控制、获取敏感数据,或在能够上传并包含 文件的场景下实现代码执行
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| arraytics | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce | 0 ~ 4.1.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15406 | 7.5 HIGH | Eventin <= 4.1.22 - Authenticated (Custom+) Local File Inclusion via 'event_layout' Parame |
| CVE-2026-12956 | 5.3 MEDIUM | Eventin <= 4.1.22 - Missing Authorization to Unauthenticated Arbitrary Order Creation and |
No comments yet