PT-2025-41661 · WordPress · Ovatheme Events Manager

Foxyyy

+1

·

Published

2025-10-11

·

Updated

2025-10-16

·

CVE-2025-6553

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ovatheme Events Manager plugin for WordPress versions up to and including 1.8.5
Description The Ovatheme Events Manager plugin for WordPress is susceptible to arbitrary file uploads because of a lack of file type validation. This occurs in the process checkout() function. This allows unauthenticated attackers to upload arbitrary files to the server, potentially leading to remote code execution (RCE).
Recommendations Update the Ovatheme Events Manager plugin to a version newer than 1.8.5.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-6553

Affected Products

Ovatheme Events Manager