CVE-2026-13170: Unknown Eventin

High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.

The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files.

Affected products

  • Unknown Eventin: before 4.1.20 (fixed in 4.1.20)

Published 2026-08-10. Last modified 2026-08-26.