Description
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
Published: 2026-08-24
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated PHP Object Injection flaw in WordPress The Events Calendar plugin up to version 6.17.2. Because object deserialization can be manipulated through external input, the flaw may enable arbitrary code execution on the server. The weakness is classified under CWE-502, highlighting a deserialization issue that can be leveraged to alter program state or execute malicious code.

Affected Systems

Nexcess The Events Calendar plugin for WordPress. All installations running version 6.17.2 or earlier are potentially vulnerable. The vulnerability is tied to the plugin’s version and not to specific host configurations beyond that scope.

Risk and Exploitability

The CVSS score of 9.8 classifies this flaw as critical, and the EPSS score is currently not available, indicating insufficient data on exploitation frequency but a likely high risk due to its severity and public availability. The flaw is not listed in the CISA KEV catalog. Based on the unauthenticated nature of the injection and typical HTTP request paths to the plugin’s endpoints, attackers could exploit the vulnerability over the network without needing any user credentials.

Generated by OpenCVE AI on August 24, 2026 at 22:26 UTC.

Remediation

Vendor Solution

Update the WordPress The Events Calendar Plugin to the latest available version (at least 6.17.3).


OpenCVE Recommended Actions

  • Update The Events Calendar Plugin to at least version 6.17.3.
  • If an update cannot be applied immediately, temporarily disable the plugin until the patch is installed.
  • Restrict access to the plugin’s administration and public endpoints to only trusted users, effectively blocking unauthenticated exploitation attempts.

Generated by OpenCVE AI on August 24, 2026 at 22:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
Title WordPress The Events Calendar plugin <= 6.17.2 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-24T21:31:32.805Z

Reserved: 2026-08-24T07:37:35.411Z

Link: CVE-2026-78265

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-24T22:17:20.407

Modified: 2026-08-24T22:17:20.407

Link: CVE-2026-78265

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:30:04Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data