Impact
The vulnerability is an unauthenticated PHP Object Injection flaw in WordPress The Events Calendar plugin up to version 6.17.2. Because object deserialization can be manipulated through external input, the flaw may enable arbitrary code execution on the server. The weakness is classified under CWE-502, highlighting a deserialization issue that can be leveraged to alter program state or execute malicious code.
Affected Systems
Nexcess The Events Calendar plugin for WordPress. All installations running version 6.17.2 or earlier are potentially vulnerable. The vulnerability is tied to the plugin’s version and not to specific host configurations beyond that scope.
Risk and Exploitability
The CVSS score of 9.8 classifies this flaw as critical, and the EPSS score is currently not available, indicating insufficient data on exploitation frequency but a likely high risk due to its severity and public availability. The flaw is not listed in the CISA KEV catalog. Based on the unauthenticated nature of the injection and typical HTTP request paths to the plugin’s endpoints, attackers could exploit the vulnerability over the network without needing any user credentials.
OpenCVE Enrichment