Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Xylus Themes XT Event Widget for Social Events allows PHP Local File Inclusion. This issue affects XT Event Widget for Social Events: from n/a through 1.1.7.
CVE ID: CVE-2025-47531
CVSS Base Severity: HIGH
CVSS Base Score: 7.5
CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendor: Xylus Themes
Product: XT Event Widget for Social Events
EPSS Score: 0.13% (probability of being exploited)
EPSS Percentile: 33.38% (scored less or equal to compared to others)
EPSS Date: 2025-06-05 (when was this score calculated)