CVE-2026-95606: WordPress The Events Calendar plugin <= 6.17.4 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection.
This issue affects The Events Calendar: from n/a through 6.17.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress The Events Calendar Pluginto a version that resolves this vulnerability.Fixed in 6.17.4.1
Event History
Frequently Asked Questions
Which installations are affected?
The affected software is StellarWP The Events Calendar, with versions through 6.17.4 in scope. The available information does not identify a lower affected version bound.
Does exploitation require authentication or user interaction?
No. The CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
What is the potential impact of successful exploitation?
The CVSS vector rates confidentiality, integrity, and availability impact as high. The vulnerability is classified as critical with a CVSS score of 9.8.