Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Xylus Themes XT Event Widget for Social Events allows PHP Local File Inclusion. This issue affects XT Event Widget for Social Events: from n/a through 1.1.7.
References
Configurations
Configuration 1 (hide)
|
History
12 Jan 2026, 14:49
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://patchstack.com/database/wordpress/plugin/xt-facebook-events/vulnerability/wordpress-xt-event-widget-for-social-events-1-1-7-local-file-inclusion-vulnerability?_s_id=cve - Third Party Advisory | |
| CPE | cpe:2.3:a:xylusthemes:xt_event_widget_for_social_events:*:*:*:*:*:wordpress:*:* | |
| First Time |
Xylusthemes
Xylusthemes xt Event Widget For Social Events |
08 May 2025, 14:39
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
07 May 2025, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-05-07 15:16
Updated : 2026-01-12 14:49
NVD link : CVE-2025-47531
Mitre link : CVE-2025-47531
CVE.ORG link : CVE-2025-47531
JSON object : View
Products Affected
xylusthemes
- xt_event_widget_for_social_events
CWE
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
