CVE-2025-26967: WordPress Events Calendar for GeoDirectory plugin <= 2.3.14 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in Stiofan Events Calendar for GeoDirectory events-for-geodirectory allows Object Injection.This issue affects Events Calendar for GeoDirectory: from n/a through <= 2.3.14.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26967?
CVE-2025-26967 has been classified as a critical severity vulnerability due to its potential for object injection.
How do I fix CVE-2025-26967?
To fix CVE-2025-26967, update the Stiofan Events Calendar for GeoDirectory plugin to version 2.3.15 or later.
What versions are affected by CVE-2025-26967?
CVE-2025-26967 affects all versions of Stiofan Events Calendar for GeoDirectory from n/a through 2.3.14.
What type of vulnerability is CVE-2025-26967?
CVE-2025-26967 is a deserialization of untrusted data vulnerability that allows for object injection.
Who should be concerned about CVE-2025-26967?
Users and administrators of Stiofan Events Calendar for GeoDirectory versions up to 2.3.14 should be concerned about CVE-2025-26967.