CVE-2025-49321: Themewinter Eventin
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arraytics Eventin wp-event-solution allows Reflected XSS.This issue affects Eventin: from n/a through <= 4.0.28.
Affected products
- Themewinter Eventin: before 4.0.29 (fixed in 4.0.29)
Published 2025-06-27. Last modified 2026-06-17.