📦 Eventin

by Themewinter

🔍 What is Eventin?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-47539

CRITICAL CVSS 9.8 May 23, 2025

This vulnerability allows attackers to escalate privileges in the Themewinter Eventin WordPress plugin, potentially gaining administrative access. It affects all WordPress sites running Eventin versio...

CVE-2025-4796

HIGH CVSS 8.8 Aug 8, 2025

The Eventin WordPress plugin has a privilege escalation vulnerability that allows attackers with contributor-level permissions or higher to change any user's email address, including administrators. T...

CVE-2025-49321

HIGH CVSS 7.1 Jun 27, 2025

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Eventin WordPress plugin. When users visit a specially crafted URL, the scripts execute in their browser...

CVE-2025-39584

HIGH CVSS 7.5 Apr 16, 2025

This vulnerability allows attackers to include local files on the server through improper input validation in the Eventin WordPress plugin. Attackers can potentially read sensitive files or execute co...

CVE-2025-26964

HIGH CVSS 7.5 Feb 25, 2025

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affects WordPress sites using the Eventin plugin (forme...

CVE-2024-7149

HIGH CVSS 8.8 Sep 27, 2024

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to perform Local File Inclusion attacks in the Eventin plugin. Attackers can include and execute arbitra...

CVE-2024-56213

MEDIUM CVSS 6.5 Dec 31, 2024

This path traversal vulnerability in the Eventin WordPress plugin allows attackers to access files outside the intended directory using '.../...//' sequences. It affects WordPress sites using Eventin ...

CVE-2023-49756

MEDIUM CVSS 5.4 Dec 9, 2024

This CVE describes a Missing Authorization vulnerability in the Themewinter Eventin WordPress plugin that allows authenticated users to exploit incorrectly configured access control security levels. T...

CVE-2024-37507

MEDIUM CVSS 6.5 Jul 21, 2024

This stored cross-site scripting (XSS) vulnerability in the Eventin WordPress plugin allows attackers to inject malicious scripts into web pages that are then executed when other users view those page...

CVE-2024-6033

MEDIUM CVSS 4.3 Jul 17, 2024

This vulnerability in the Eventin WordPress plugin allows authenticated attackers with Contributor-level access or higher to import unauthorized data (events, speakers, schedules, attendee data) due t...