Description
WordPress Plugin Eventify-Simple Events is prone to a remote file include vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible. WordPress Plugin Eventify-Simple Events version 1.7.g is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.7.h or latest
References
Related Vulnerabilities
WordPress Plugin Remove WP Update Nags Security Bypass (1.3.0)
WordPress Plugin Poll Maker Cross-Site Scripting (3.2.8)
e107 Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-17081)
WordPress Plugin Simple Job Board Directory Traversal (2.9.3)
WordPress Plugin WP with Spritz Local/Remote File Inclusion (1.0)