Unrestricted File Upload Vulnerability in Ovatheme Events Manager
CVE-2025-32510
10CRITICAL
What is CVE-2025-32510?
The Ovatheme Events Manager plugin for WordPress has a vulnerability that permits the unrestricted uploading of files with potentially dangerous types. This flaw enables attackers to upload malicious files to the server, which could be executed to compromise the site and its users. The vulnerability affects versions from n/a to 1.7.5, necessitating immediate attention to ensure the security of websites utilizing this plugin.
Affected Version(s)
Ovatheme Events Manager <= 1.7.5