[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#Local File Inclusion

blogHIGH 7.5

Understanding and Defending Against Local File Inclusion Vulnerability in Eventin WordPress Plugin

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion (LFI) due to a flaw in the 'event_layout' parameter. This allows authenticated attackers with contributor-level access to include and execute arbitrary PHP files on the server. The vulnerability has a CVSS score of 7.5 and is classified under CWE-98.

Sep 10, 20261 source
newsHIGH 7.5

CVE-2026-15406: Local File Inclusion Vulnerability in Eventin WordPress Plugin

The Eventin WordPress plugin is vulnerable to Local File Inclusion (LFI) in versions up to 4.1.22. Authenticated attackers with custom-level access can exploit this flaw to execute arbitrary PHP code, bypass access controls, and obtain sensitive data. A CVSS score of 7.5 indicates a high severity level.

Sep 10, 20261 source
newsCRITICAL 9.8

Critical Local File Inclusion Vulnerability in Divi Ajax Filter Plugin

The Divi Ajax Filter plugin for WordPress has a critical Local File Inclusion vulnerability (CVE-2026-11613) with a CVSS score of 9.8, affecting all versions up to 5.1.2. Unauthenticated attackers can exploit this vulnerability to execute arbitrary PHP code on the server. Immediate action is required to mitigate this vulnerability.

Sep 5, 20261 source