High · 7.0 WordPress CVE-2026-95606
Critical PHP Object Injection Vulnerability in The Events Calendar WordPress Plugin (CVE-2026-95606)
A critical deserialization flaw (CVE-2026-95606, CVSS 9.8) in The Events Calendar WordPress plugin allows unauthenticated attackers to perform PHP object injection. No fixed version has been confirmed at the time of writing.
AI summary
A critical vulnerability has been disclosed in The Events Calendar, a widely used WordPress plugin developed by Liquid Web / StellarWP. The flaw, tracked as CVE-2026-95606, involves deserialization of untrusted data and can lead to PHP object injection. It affects versions of the plugin through 6.17.4 and carries a maximum CVSS base score of 9.8, reflecting its potential for severe impact with minimal attacker effort.
What Happened
A deserialization of untrusted data vulnerability (CWE-502) was identified in The Events Calendar WordPress plugin. The issue allows an attacker to trigger PHP Object Injection by supplying crafted serialized data that the plugin processes without proper validation. The vulnerability is tracked as CVE-2026-95606.
Technical Cause
The vulnerability stems from unsafe deserialization of untrusted input (CWE-502). When an application deserializes attacker-controlled data without adequate safeguards, it can allow injection of arbitrary PHP objects. Depending on the classes available in the application's autoload chain, such object injection can potentially be leveraged for further exploitation, including remote code execution, though the fact package does not confirm a specific downstream exploitation chain for this plugin.
Why It Matters
The vulnerability has a CVSS 3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating it can be exploited remotely over the network, requires no authentication, no user interaction, and low attack complexity. A successful exploit could result in high impact to confidentiality, integrity, and availability of the affected site.
Who Is Affected
Any WordPress site running The Events Calendar plugin through version 6.17.4 is potentially affected. The plugin is widely deployed, which increases the overall exposure across the WordPress ecosystem.
Affected Versions
The Events Calendar versions through 6.17.4 are listed as affected. The advisory references version 6.17.4.1 as the boundary marking the fixed release in the affected-range data, but the fact package does not confirm that a fix has actually been published (fix_available is marked false). Site owners should treat this as an open question pending vendor confirmation.
Fixes and Mitigation
At the time of this briefing, no fix has been confirmed as available according to the fact package, despite affected-range data referencing version 6.17.4.1 as a boundary. This is a notable inconsistency in the available data. Site owners should check directly with the plugin vendor or the WordPress plugin repository for the latest official release information before assuming a patched version exists.
Recommended Action
Site owners running The Events Calendar should verify their installed version, consult the official plugin page or vendor channels for an updated release addressing CVE-2026-95606, and apply any available update as soon as it is confirmed. Until a fix is verified, consider additional monitoring or temporary mitigations such as restricting access to the plugin's input-handling endpoints where feasible.
PatchBriefing score
7.0 / 10 · High
Official CVSS: 9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Why this score
This vulnerability receives a PatchBriefing score of 7 out of 10. The score is driven primarily by the CVSS base score of 9.8, which reflects the critical technical severity of an unauthenticated, no-interaction, remotely exploitable flaw with high impact to confidentiality, integrity, and availability. Additional contributing factors include the lack of a confirmed fix and the plugin's substantial install base (approximately 600,000 sites), both of which increase real-world risk. The score is moderated by the absence of confirmed active exploitation, no known public exploit code, and no available EPSS data at this time.
Affected versions
- The Events Calendar < 6.17.4.1
- vulnerable
Reported fixes
At the time of this briefing, no fix has been confirmed as available according to the fact package, despite affected-range data referencing version 6.17.4.1 as a boundary. This is a notable inconsistency in the available data. Site owners should check directly with the plugin vendor or the WordPress plugin repository for the latest official release information before assuming a patched version exists.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
WPVulnerability database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email