CVSS
7.2
CVSS v3.1
EPSS
0.4%
Exploit Prediction Score
Published
August 10, 2026
Exploitability
EPSS probability 0.4%
The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).