Junglewise Threat Intelligence

CVE-2026-15406: Eventin Local File Inclusion in event_layout parameter

CVE-2026-15406 · Severity: high · CVSS 7.5 · Published 2026-09-09

Technologies: Nevesco Eventin.

Executive brief

Eventin is a WordPress plugin used for managing event calendars, registrations, and ticket bookings. Authenticated users with custom-level access or higher can exploit a file inclusion vulnerability to load and execute arbitrary PHP files on the server, potentially exposing sensitive data or gaining full control over the website.

Technical details

The vulnerability is a Local File Inclusion (LFI) flaw in the 'event_layout' parameter affecting all versions up to 4.1.22. The vulnerable component fails to properly sanitize or validate file path inputs before including PHP files via include/require statements. An authenticated attacker with custom-level access or above can exploit this by manipulating the event_layout parameter to include arbitrary .php files from the server, leading to arbitrary PHP code execution. This is particularly dangerous when combined with the ability to upload PHP files. No patch status is currently indicated.

Affected products

  • Nevesco Eventin up to and including 4.1.22

Timeline

  • 2026-09-09: disclosed

References