Themewinter Eventin contains a path traversal caused by relative path manipulation, letting attackers access arbitrary files on the server, exploit requires no specific privileges or user interaction.
id: CVE-2025-47445
info:
name: WordPress Eventin (Themewinter) ≤ 4.0.26 - Arbitrary File Download
...