Description
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 4.0.26 via the proxy_image() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. CVE-2025-47445 is a duplicate of this vulnerability.
Problem types
CWE-73 External Control of File Name or Path
Product status
Any version
Timeline
| 2025-05-07: | Disclosed |
Credits
Michael Mazzolini
References
www.wordfence.com/...-85c3-41fd-8ad7-f0dee32f201b?source=cve
plugins.trac.wordpress.org/...ion/trunk/core/Admin/Hooks.php