Description
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection.

This issue affects The Events Calendar: from n/a through 6.17.4.
Published: 2026-10-07
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a deserialization of untrusted data that allows PHP object injection in the Liquid Web / StellarWP The Events Calendar WordPress plugin. The flaw can enable an attacker to execute arbitrary PHP code on the affected server, potentially compromising the entire web application, data, and infrastructure. A CVSS score of 9.8 indicates that the impact is severe and the risk of exploitation is high should an attacker target this plugin.

Affected Systems

The issue affects all installed versions of the Liquid Web / StellarWP The Events Calendar plugin from the earliest release through 6.17.4. Plugin users running any of these versions are susceptible until they update to 6.17.4.1 or later. The vulnerability applies only to the WordPress plugin and does not affect the core WordPress installation directly.

Risk and Exploitability

The high CVSS rating of 9.8 and lack of mitigation evidence in the CISA KEV catalog suggest that this flaw presents a critical opportunity for attackers. While the EPSS score is not available, the nature of the flaw—object injection via deserialization—implies that malicious payloads can be delivered through crafted HTTP requests or plugin inputs. The attack vector is likely remote, with no local privilege or user interaction required, and can lead to full system compromise if the attacker can execute code.

Generated by OpenCVE AI on October 7, 2026 at 18:56 UTC.

Remediation

Vendor Solution

Update the WordPress The Events Calendar Plugin to the latest available version (at least 6.17.4.1).


OpenCVE Recommended Actions

  • Update the WordPress The Events Calendar Plugin to version 6.17.4.1 or later.
  • Keep the WordPress core and all other plugins up to date to reduce the attack surface.
  • Deploy a web application firewall or similar security layer to block malicious payloads targeting deserialization endpoints.

Generated by OpenCVE AI on October 7, 2026 at 18:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection. This issue affects The Events Calendar: from n/a through 6.17.4.
Title WordPress The Events Calendar plugin <= 6.17.4 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-07T17:49:58.857Z

Reserved: 2026-09-22T09:18:20.380Z

Link: CVE-2026-95606

cve-icon Vulnrichment

Updated: 2026-10-07T17:49:51.927Z

cve-icon NVD

Status : Received

Published: 2026-10-07T17:17:04.213

Modified: 2026-10-07T18:17:31.910

Link: CVE-2026-95606

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T19:00:16Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data