Skip to content

Known CVE

EventON Lite <= 2.4 - Authenticated Local File Inclusion

Ashan Perera EventON contains a PHP remote file inclusion caused by improper control of filename in include/require statements, letting attackers include local files, exploit requires attacker to control include filename.

CVE-2025-32614

High2025CVSS 8.8CWE-98

cve2025 · wordpress · wp-plugin · lfi · eventon · authenticated · wp

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website