PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-15406 Eventin CVE debrief

The Eventin plugin for WordPress is vulnerable to Local File Inclusion, allowing authenticated attackers with custom-level access and above to execute arbitrary PHP code. This vulnerability affects WordPress administrators, security teams, and users with custom-level access, potentially leading to bypassed access controls, obtained sensitive data, or achieved code execution in cases where .php file types can be uploaded and included. The CVE record and NVD entry provide details on the vulnerability, but the scope of affected versions and potential impact require further verification.

Vendor
Eventin
Product
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-09
Original CVE updated
2026-09-11
Advisory published
2026-09-09
Advisory updated
2026-09-11

Who should care

WordPress administrators, security teams, and users with custom-level access and above should assess exposure and apply patches as a high priority. They should also review compensating controls for exposed systems, monitor for suspicious activity, and track exceptions and remediation efforts.

Why it matters

The CVE-2026-15406 vulnerability in the Eventin plugin for WordPress allows authenticated attackers to execute arbitrary PHP code, bypass access controls, and obtain sensitive data. WordPress administrators and security teams should assess exposure and apply patches as a high priority.

  • Execution of arbitrary PHP code in .php files
  • Bypassing access controls and obtaining sensitive data
  • Potential code execution in cases where .php file types can be uploaded and included

Technical summary

The Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter. This allows authenticated attackers with custom-level access and above to include and execute arbitrary .php files on the server, potentially leading to bypassed access controls, obtained sensitive data, or achieved code execution in cases where .php file types can be uploaded and included. The vulnerability affects WordPress administrators, security teams, and users with custom-level access.

Defensive priority

High priority for WordPress administrators and security teams to assess exposure and apply patches.

Recommended defensive actions

  • Assess exposure and apply patches for the Eventin plugin
  • Verify custom-level access and above for potential exploitation
  • Monitor for suspicious .php file inclusions
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but the scope of affected versions and potential impact require further verification. The Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter. This makes it possible for authenticated attackers, with custom-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-15406 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-15406

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-15406 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15406

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.15/core/AccessControl/Permission.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.15/core/event/Api/EventController.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.15/core/event/template-functions.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.16/core/AccessControl/Permission.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.16/core/event/Api/EventController.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.16/core/event/template-functions.php

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.