WordPress Event post plugin <= 5.9.5 - Local File Inclusion vulnerability
43Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Actcvss 7.5epss 0.5%
from disclosure to weapon
Published on NVDJul 12
VulnCheckJul 11
exploitation probability
0.5%top 57% of all CVEs
observed exploitation
yesVulnCheck
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Bastien Ho Event post event-post.This issue affects Event post: from n/a through <= 5.9.5.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
Bastien Ho · Event post