Local File Inclusion Flaw in Event Calendar Plugin for WordPress
CVE-2026-15667

7.5HIGH

What is CVE-2026-15667?

The Event Calendar, Event Registration, Tickets & Booking plugin for WordPress allows authenticated users with contributor-level access to exploit a Local File Inclusion (LFI) vulnerability through the 'event_layout' parameter. This issue affects all versions up to and including 4.1.22, potentially enabling attackers to include and execute arbitrary PHP files stored on the server. As the etn_manage_event capability is assigned to Contributors by default, they can manipulate the REST API to set malicious values for event_layout, leading to unauthorized access to sensitive data or even complete code execution if PHP files can be uploaded to the server.

Affected Version(s)

Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce 0 <= 4.1.22

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.