CVE-2026-97257: WordPress Simple Event Planner plugin <= 1.5.7 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
simple-event-plannerto a version that resolves this vulnerability.Fixed in 1.5.8
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability is rated PR:L, indicating that an attacker needs low-level privileges before exploitation. It does not require user interaction and is reachable over the network.
Which installations are affected?
Simple Event Planner versions through 1.5.7 are affected. The available information does not identify a fixed version or indicate whether any particular plugin configuration is unaffected.
What impact could successful exploitation have?
The CVSS vector indicates high impacts to confidentiality, integrity, and availability. The issue is an unsafe deserialization condition that can permit PHP object injection.