CVE-2026-13170EPSS p5.7%
CVE-2026-13170CVE-2026-13170
Description
The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files.
Scoring
| EPSS | 0.16% probability of exploitation · percentile 5.7% · 2026-08-11T12:00:17Z |
| Last modified | 2026-08-10 |