Local File Inclusion Vulnerability in Events Made Easy Plugin for WordPress
CVE-2026-75963

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 August 2026

What is CVE-2026-75963?

The Events Made Easy plugin for WordPress has a Local File Inclusion vulnerability that affects all versions up to and including 3.2.5. This vulnerability is triggered through the eme_single_event_page_template function, enabling authenticated users with contributor-level access or higher to include and execute arbitrary .php files on the server. This loophole can be exploited to bypass access controls and execute potentially malicious PHP code, leading to unauthorized data access or execution of harmful scripts. The issue occurs passively when users visit the affected single-event page, requiring no additional interaction from the attacker post-submission.

Affected Version(s)

Events Made Easy 0 <= 3.2.5

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.