Description
WordPress Plugin Eventify-Simple Events is prone to a remote file include vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible. WordPress Plugin Eventify-Simple Events version 1.7.g is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.7.h or latest
References
Related Vulnerabilities
WordPress Plugin Tabs-Responsive Tabs with WooCommerce Product Tab Extension Security Bypass (3.6.0)
WordPress Plugin Quick Cache (Speed Without Compromise) Unspecified Vulnerability (140725)
WordPress Plugin Coming soon and Maintenance mode Cross-Site Scripting (3.5.2)
WordPress Plugin Thrive Architect Security Bypass (2.6.7.3)
WordPress Plugin Translate WordPress-Google Language Translator Cross-Site Scripting (4.0.9)