Description
Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.
Published: 2026-06-25
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

EventPrime plugin versions up to 4.3.4.1 allow PHP Object Injection, a flaw where arbitrary PHP objects can be deserialized from untrusted input. The vulnerability is a CWE‑502 weakness that can enable attackers to execute arbitrary code, modify data, or gain elevated privileges once the plugin processes malicious serialized payloads.

Affected Systems

Any WordPress installation running the EventPrime plugin by EventPrime, in versions 4.3.4.1 or earlier.

Risk and Exploitability

The flaw scores 8.8 on CVSS, indicating high severity. No EPSS data is available, so exploitation likelihood cannot be quantified, and the vulnerability is not yet listed in CISA KEV. Based on the description, it is inferred that the attack vector involves an authenticated user with access to the subscriber component who can supply crafted serialized data to trigger the injection.

Generated by OpenCVE AI on June 25, 2026 at 16:18 UTC.

Remediation

Vendor Solution

Update the WordPress EventPrime Plugin to the latest available version (at least 4.3.4.2).


OpenCVE Recommended Actions

  • Upgrade the EventPrime WordPress plugin to version 4.3.4.2 or later.
  • If the EventPrime plugin is not required for your site's functionality, uninstall it completely from the WordPress installation.
  • Restrict access to the subscriber functionality to trusted administrators only and ensure that no unauthenticated or low‑privilege users can supply serialized data to the plugin.

Generated by OpenCVE AI on June 25, 2026 at 16:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 25 Jun 2026 14:00:00 +0000

Type Values Removed Values Added
Description Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.
Title WordPress EventPrime plugin <= 4.3.4.1 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-06-25T23:23:16.436Z

Reserved: 2026-06-18T14:38:04.420Z

Link: CVE-2026-56053

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-25T16:30:15Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data