Unrestricted File Upload Vulnerability in Ovatheme Events Manager
CVE-2025-32510

10CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 June 2025

What is CVE-2025-32510?

The Ovatheme Events Manager plugin for WordPress has a vulnerability that permits the unrestricted uploading of files with potentially dangerous types. This flaw enables attackers to upload malicious files to the server, which could be executed to compromise the site and its users. The vulnerability affects versions from n/a to 1.7.5, necessitating immediate attention to ensure the security of websites utilizing this plugin.

Affected Version(s)

Ovatheme Events Manager <= 1.7.5

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bonds (Patchstack Alliance)
.
CVE-2025-32510 : Unrestricted File Upload Vulnerability in Ovatheme Events Manager