Understanding and Defending Against Local File Inclusion Vulnerability in Eventin WordPress Plugin
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion (LFI) due to a flaw in the 'event_layout' parameter. This allows authenticated attackers with contributor-level access to include and execute arbitrary PHP files on the server. The vulnerability has a CVSS score of 7.5 and is classified under CWE-98.