VYPR
Unrated severityNVD Advisory· Published Sep 5, 2026

Eventin < 4.1.21 - Contributor+ LFI via Event Layout Meta

CVE-2026-84898

Description

The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with contributor-level access and above to include and execute arbitrary local PHP files.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.