Product
The Events Made Easy WordPress plugin is vulnerable to authenticated Local File Inclusion via the eme_single_event_page_template function, allowing contributors to execute arbitrary PHP code.