Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Xylus Themes XT Event Widget for Social Events allows PHP Local File Inclusion. This issue affects XT Event Widget for Social Events: from n/a through 1.1.7.
Metrics
Affected Vendors & Products
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 07 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Xylus Themes XT Event Widget for Social Events allows PHP Local File Inclusion. This issue affects XT Event Widget for Social Events: from n/a through 1.1.7. | |
| Title | WordPress XT Event Widget for Social Events <= 1.1.7 - Local File Inclusion Vulnerability | |
| Weaknesses | CWE-98 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published: 2025-05-07T14:20:11.860Z
Updated: 2025-05-07T18:18:16.274Z
Reserved: 2025-05-07T09:39:46.952Z
Link: CVE-2025-47531
Updated: 2025-05-07T17:19:29.787Z
Status : Awaiting Analysis
Published: 2025-05-07T15:16:10.197
Modified: 2025-05-08T14:39:18.800
Link: CVE-2025-47531
No data.