Impact
The Event Calendar plugin for WordPress contains a PHP object injection flaw that leads to remote code execution, consistent with CWE‑502. The weakness lies in the is_safe_widget_instance function, which fails to prevent PHP magic methods from being invoked during pre‑parse. By forging a valid wp_hash integrity attribute, an attacker can supply a serialized payload that bypasses normal checks and is executed during event rendering. The unserialized object is processed with the privileges of the web server, allowing arbitrary code execution by an unauthenticated user.
Affected Systems
WordPress sites running the StellarWP Event Calendar plugin up to and including version 6.17.4 are affected. The vulnerability is triggered when the plugin’s V2 single‑event template executes do_blocks() on buffered comment HTML. It requires that comments be enabled and visible for the event post type; no authenticated access is necessary.
Risk and Exploitability
The CVSS score of 9.8 marks the flaw as critical, while the EPSS score of less than 1% indicates that exploitation has not yet been widely observed. The flaw is not listed in the CISA KEV catalog, so no widespread exploit code is known. An attacker can craft a malicious comment or request that includes the forged payload, and because the plugin renders the comment markup. The exploit requires only the ability to post a comment on an event page or to send a request to the event rendering endpoint.
OpenCVE Enrichment