PT-2025-34519 · WordPress · Eventin

Gai Tanaka

·

Published

2025-08-23

·

Updated

2025-08-23

·

CVE-2025-7813

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Eventin plugin for WordPress versions through 4.0.37
Description: The Eventin plugin for WordPress is susceptible to Server-Side Request Forgery (SSRF) via the proxy image function. This allows unauthenticated attackers to make web requests to arbitrary locations originating from the web application, potentially enabling them to query and modify information from internal services.
Recommendations: Update the Eventin plugin to a version later than 4.0.37.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-7813

Affected Products

Eventin