Local File Inclusion Flaw in Event Calendar Plugin for WordPress
CVE-2026-15667
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 September 2026
What is CVE-2026-15667?
The Event Calendar, Event Registration, Tickets & Booking plugin for WordPress allows authenticated users with contributor-level access to exploit a Local File Inclusion (LFI) vulnerability through the 'event_layout' parameter. This issue affects all versions up to and including 4.1.22, potentially enabling attackers to include and execute arbitrary PHP files stored on the server. As the etn_manage_event capability is assigned to Contributors by default, they can manipulate the REST API to set malicious values for event_layout, leading to unauthorized access to sensitive data or even complete code execution if PHP files can be uploaded to the server.
Affected Version(s)
Eventin β Event Calendar, Tickets, Registration, Booking & WooCommerce 0 <= 4.1.22