Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-13170 | 2 Eventin, Wordpress | 2 Eventin, Wordpress | 2026-08-10 | N/A |
| The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files. | ||||
| CVE-2026-13178 | 2 Eventin, Wordpress | 2 Eventin, Wordpress | 2026-07-30 | 7.5 High |
| The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment. | ||||
Page 1 of 1.