CVE-2026-75963

Events Made Easy <= 3.2.5 - Authenticated (Contributor+) Local File Inclusion via 'wp_page_template' Event Property

The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The stored traversal payload is triggered passively when any visitor loads the affected single-event page, meaning post-submission execution does not require additional attacker interaction.


We have discovered 1,161 live websites that are affected by CVE-2026-75963.

Run a Free Instant Scan




Affected Software

Product  Events Made Easy
Category Wordpress Plugins
Vulnerable Domains1,161 live websites (100% of Events Made Easy install base)
Vulnerable Versions
  • from 0 through 3.2.5
Vulnerable Versions Count149 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')



Details

  • Published - Aug 20, 2026
  • Updated - Aug 20, 2026

Credits

  • Wordfence PRISM (finder)

Website Distribution by Country

Number of websites using CVE-2026-75963
United States286 websites



Germany407 websites
Netherlands74 websites
France55 websites
GB44 websites
Switzerland42 websites
Austria32 websites
Denmark27 websites
Italy25 websites
Sweden16 websites

Website Distribution by TLD

Number of websites using CVE-2026-75963
.de338 websites
.com188 websites
.org128 websites
.nl68 websites
.at45 websites
.ch41 websites
.fr28 websites
.co.uk21 websites
.it21 websites
.dk19 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-75963

Top websites that are affected by CVE-2026-75963. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.********.gov United States***,***
**********.be United States***,***
*********.org Germany***,***
*********.********.gov United States***,***
************.de Germany***,***
*****.de Germany***,***
****.********.gov United States***,***
**********.com United States***,***
***.nrw Germany***,***
****.**.gov United States***,***
See full domain list

FAQ

CVE-2026-75963 is Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') in Events Made Easy
A total of 1,161 websites have been identified as vulnerable to CVE-2026-75963, based on global website indexing conducted by WebTechSurvey.
The Events Made Easy is affected by the CVE-2026-75963 vulnerability.
Events Made Easy versions up to and including 3.2.5 are vulnerable to CVE-2026-75963.