nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-38735 CVE-2024-38735
HIGH
WordPress Event post plugin <= 5.9.5 - Local File Inclusion vulnerability
Record summary
CVE-2024-38735 has a selected CVSS score of 7.5 (high).
Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Bastien Ho Event post event-post.This issue affects Event post: from n/a through <= 5.9.5.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 11, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 12, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Event postBrowse Bastien Ho / Event postDefault status: unaffected | CVE List | Through 5.9.5 | affected |
event_postBrowse avecnous / event_post | VulnCheck | Version data not supplied | |
Default status: unknown | CVE List | Through 5.9.5 | affected |
References
3patchstack.comvdb entry
https://patchstack.com/database/Wordpress/Plugin/event-post/vulnerability/wordpress-event-post-plugin-5-9-5-local-file-inclusion-vulnerability?_s_id=cve patchstack.comvdb entry
https://patchstack.com/database/vulnerability/event-post/wordpress-event-post-plugin-5-9-5-local-file-inclusion-vulnerability?_s_id=cve