WordPress Eventin (Themewinter) ≤ 4.0.26 - Arbitrary File Download
CVE-2025-47445
Verified
Description
Themewinter Eventin contains a path traversal caused by relative path manipulation, letting attackers access arbitrary files on the server, exploit requires no specific privileges or user interaction.
Severity
High
CVSS Score
7.5
Exploit Probability
5%
Published Date
December 3, 2025
Template Author
hnd3884
CVE-2025-47445.yaml
7.5Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2025-47445
CWE ID:
cwe-23
Remediation Steps
Update to the latest version of Eventin, version 4.0.27 or later.