Local File Inclusion Vulnerability in Events Made Easy Plugin for WordPress
CVE-2026-75963
7.5HIGH
What is CVE-2026-75963?
The Events Made Easy plugin for WordPress has a Local File Inclusion vulnerability that affects all versions up to and including 3.2.5. This vulnerability is triggered through the eme_single_event_page_template function, enabling authenticated users with contributor-level access or higher to include and execute arbitrary .php files on the server. This loophole can be exploited to bypass access controls and execute potentially malicious PHP code, leading to unauthorized data access or execution of harmful scripts. The issue occurs passively when users visit the affected single-event page, requiring no additional interaction from the attacker post-submission.
Affected Version(s)
Events Made Easy 0 <= 3.2.5