Unrated severityNVD Advisory· Published Sep 5, 2026
Eventin < 4.1.21 - Contributor+ LFI via Event Layout Meta
CVE-2026-84898
Description
The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with contributor-level access and above to include and execute arbitrary local PHP files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/d8dea263-5676-4e3c-9ea4-36904e1ac4d3/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.