NVD disclosure day

Published threat advisories for October 11, 2025

CVE advisoryCRITICAL

CVE-2025-6553

Ovatheme Events Manager Arbitrary File Upload Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The Ovatheme Events Manager WordPress plugin has a critical vulnerability allowing unauthenticated attackers to upload arbitrary files to the server, potentially leading to remote code execution. This issue is relevant to public-facing websites that use the plugin for event management and checkout processes.