{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/themewinter/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:themewinter:eventin:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-15667"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Eventin (\u003c= 4.1.22)"],"_cs_severities":["high"],"_cs_tags":["lfi","vulnerability","wordpress","webserver"],"_cs_type":"advisory","_cs_vendors":["Themewinter"],"content_html":"\u003cp\u003eThe Eventin WordPress plugin (versions 4.1.22 and earlier) contains a Local File Inclusion (LFI) vulnerability identified as CVE-2026-15667. The flaw resides in the handling of the 'event_layout' parameter within the plugin's REST API functionality. Authenticated users with the 'etn_manage_event' capability - which is assigned to the Contributor role by default - can exploit this parameter to point the application to arbitrary local files. If an attacker can upload a file with a .php extension to the server, this vulnerability allows them to include and execute that code, resulting in remote code execution (RCE). This issue is significant as it provides a pathway for lateral movement, privilege escalation, and sensitive data exfiltration by users who are already within the WordPress site's administrative hierarchy.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated users with contributor-level permissions to execute arbitrary PHP code on the web server. This can lead to full site compromise, unauthorized database access, the modification of system configuration files, and the exfiltration of sensitive site data. Organizations relying on this plugin for event management are vulnerable if they allow untrusted users to hold contributor-level accounts.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Eventin WordPress plugin to the latest version immediately to remediate the vulnerability associated with CVE-2026-15667.\u003c/li\u003e\n\u003cli\u003eAudit WordPress user roles and capabilities to identify accounts with the 'etn_manage_event' capability and restrict these to trusted administrators only.\u003c/li\u003e\n\u003cli\u003eImplement file integrity monitoring to detect the creation of unexpected or unauthorized .php files on the web server filesystem.\u003c/li\u003e\n\u003cli\u003eRestrict file upload directories to prevent execution (e.g., set 'noexec' flags on uploads directories) as a defense-in-depth measure.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T03:51:49Z","date_published":"2026-09-09T03:51:49Z","id":"https://feed.craftedsignal.io/briefs/2026-09-eventin-lfi/","summary":"The Eventin WordPress plugin contains a local file inclusion vulnerability in the event_layout parameter, allowing authenticated contributors to execute arbitrary PHP code.","title":"Local File Inclusion in Eventin WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-eventin-lfi/"}],"language":"en","title":"CraftedSignal Threat Feed - Themewinter","version":"https://jsonfeed.org/version/1.1"}