Beveiligingsadvies

CVE-2026-13170

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-10 06:00:14
Laatst bijgewerkt 2026-08-12 15:04:36
Toegewezen door WPScan
CVSS-score 7.2
Status PUBLISHED

Beschrijving

The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files.