---
id: CVE-2025-6553
title: >-
  The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary
  file uploads due to missing file type validation in the process_checkout()
  function in all versions up to, and including, 1.8.5
summary: >-
  The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary
  file uploads due to missing file type validation in the process_checkout()
  function in all versions up to, and including, 1.8.5. This makes it possible
  for unaut…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
published: '2025-10-11'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-6553'
references:
  - url: >-
      https://themeforest.net/item/em4u-event-management-multipurpose-wordpress-theme/20846579
    label: security@wordfence.com
  - url: >-
      https://themeforest.net/item/em4u-event-management-multipurpose-wordpress-theme/20846579#item-description__change_log
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/808392a9-dbac-4896-8677-6ddc1213d80d?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00764
epssPercentile: 0.54018
ingestedAt: '2026-10-08T13:42:55.102Z'
---

## Overview

The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_checkout() function in all versions up to, and including, 1.8.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
