Impact
This vulnerability is a deserialization of untrusted data that allows PHP object injection in the Liquid Web / StellarWP The Events Calendar WordPress plugin. The flaw can enable an attacker to execute arbitrary PHP code on the affected server, potentially compromising the entire web application, data, and infrastructure. A CVSS score of 9.8 indicates that the impact is severe and the risk of exploitation is high should an attacker target this plugin.
Affected Systems
The issue affects all installed versions of the Liquid Web / StellarWP The Events Calendar plugin from the earliest release through 6.17.4. Plugin users running any of these versions are susceptible until they update to 6.17.4.1 or later. The vulnerability applies only to the WordPress plugin and does not affect the core WordPress installation directly.
Risk and Exploitability
The high CVSS rating of 9.8 and lack of mitigation evidence in the CISA KEV catalog suggest that this flaw presents a critical opportunity for attackers. While the EPSS score is not available, the nature of the flaw—object injection via deserialization—implies that malicious payloads can be delivered through crafted HTTP requests or plugin inputs. The attack vector is likely remote, with no local privilege or user interaction required, and can lead to full system compromise if the attacker can execute code.
OpenCVE Enrichment