CVE-2026-15406: Local File Inclusion Vulnerability in Eventin WordPress Plugin
The Eventin WordPress plugin is vulnerable to Local File Inclusion (LFI) in versions up to 4.1.22. Authenticated attackers with custom-level access can exploit this flaw to execute arbitrary PHP code, bypass access controls, and obtain sensitive data. A CVSS score of 7.5 indicates a high severity level.