CVE-2025-26964·PHP vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Arraytics Eventin wp-event-solution allows PHP Local File Inclusion.This issue affects Eventin: from n/a through <= 4.0.20.
- Severity
- high
- Software
- PHP
- Fixed in
- 4.0.21
- Published
- 2025-02-25
Affected versions
Until: 4.0.21
Fixed in: 4.0.21
How to fix this CVE
Update the Eventin WordPress plugin (wp-event-solution) to version 4.0.21 or later to patch the local file inclusion vulnerability. This vulnerability allows authenticated users to access sensitive files on the server through improper file path handling in include/require statements. Apply the update immediately across all WordPress installations using this plugin.
sudo dnf update phpDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST|GET requests to wp-content/plugins/wp-event-solution/ endpoints containing file path parameters with sequences like ../, ..\ or references to /etc/passwd, /etc/shadow, wp-config.php, or other sensitive system files in query strings or POST dataWAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement WAF rules to block requests to wp-event-solution plugin endpoints containing path traversal sequences (../, .., or encoded variants %2e%2e%2f). Additionally, restrict file inclusion parameters to whitelisted file paths and prevent access to sensitive configuration files through request filtering on common WordPress configuration file names.How to check if you are affected
- Step 1: Check your PHP version by running `php -v` or accessing phpinfo() via your web server
- Step 2: Verify the Eventin plugin version in WordPress: navigate to Plugins → Installed Plugins and locate 'Eventin' or check wp-content/plugins/wp-event-solution/eventin.php for the Version field
- Step 3: Search web server logs (typically /var/log/apache2/access.log or /var/log/nginx/access.log) for suspicious file inclusion patterns such as requests containing '../../' path traversal sequences or attempts to access /etc/passwd, /etc/shadow, or wp-config.php via plugin file parameters
- Step 4: After updating, verify the plugin version is 4.0.21+ by checking the plugin details in WordPress admin panel and confirm no error logs appear related to file inclusion attempts
FAQ
What is CVE-2025-26964?
CVE-2025-26964 is a local file inclusion (LFI) vulnerability in the Eventin WordPress plugin that allows authenticated users to read arbitrary files from the server by manipulating file path parameters passed to PHP include/require statements. This could expose sensitive configuration files like wp-config.php containing database credentials.
Is CVE-2025-26964 being actively exploited?
No, this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploit code is available. However, the vulnerability requires authentication, which limits its immediate threat scope.
What versions of PHP are affected by CVE-2025-26964?
This CVE affects the Eventin WordPress plugin (wp-event-solution) through version 4.0.20. Any WordPress site running Eventin up to and including version 4.0.20 with authenticated user access is vulnerable regardless of PHP version.
How do I check if my server is vulnerable to CVE-2025-26964?
Log into your WordPress dashboard, navigate to Plugins → Installed Plugins, and check if 'Eventin' is installed with a version number of 4.0.20 or lower. You can also inspect the plugin file at wp-content/plugins/wp-event-solution/eventin.php and grep for the 'Version:' header.
Does Defensia detect CVE-2025-26964?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Eventin WordPress plugin is detected on a monitored server, CVE-2025-26964 will appear in your dashboard with remediation steps.
Related PHP CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-26964. Free for 1 server.
Get started free