PatchSiren cyber security CVE debrief
CVE-2026-95606 Liquid Web / StellarWP CVE debrief
A critical vulnerability was found in the WordPress The Events Calendar plugin, allowing for PHP Object Injection due to deserialization of untrusted data. This issue affects versions up to 6.17.4. The vulnerability has a CVSS score of 9.8 and is considered critical, potentially leading to code execution and data breaches. WordPress administrators and users of The Events Calendar plugin should assess their exposure and prioritize remediation to prevent potential exploitation. The CVE record and source item provide details on the vulnerability, but limited information is available on exploitation or affected versions beyond 6.17.4.
- Vendor
- Liquid Web / StellarWP
- Product
- The Events Calendar
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
WordPress administrators and users of The Events Calendar plugin, particularly those with versions up to 6.17.4, should assess their exposure and verify remediation status.
Why it matters
CVE-2026-95606 is a critical vulnerability in the WordPress The Events Calendar plugin, allowing for PHP Object Injection. WordPress administrators and users of affected versions should assess exposure and prioritize remediation to prevent potential code execution and data breaches.
- Potential for code execution on affected systems
- Possible data breaches due to injection vulnerability
- Need for immediate remediation to prevent exploitation
Technical summary
The Events Calendar plugin for WordPress, versions up to 6.17.4, is vulnerable to PHP Object Injection due to deserialization of untrusted data. This issue has a CVSS score of 9.8 and is considered critical. The vulnerability could allow attackers to execute code and access sensitive data. The Events Calendar plugin is widely used for event management on WordPress sites, making this vulnerability a significant concern for WordPress administrators and users of the plugin.
Defensive priority
High
Recommended defensive actions
- Assess exposure of The Events Calendar plugin versions up to 6.17.4
- Verify vendor remediation status for versions beyond 6.17.4
- Monitor for potential exploitation attempts
Evidence notes
The CVE record and source item provide details on the vulnerability, but limited information is available on exploitation or affected versions beyond 6.17.4.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-95606 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-95606
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-95606 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-95606
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
WordPress The Events Calendar plugin <= 6.17.4 - PHP Object Injection vulnerability
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/95xxx/CVE-2026-95606.json
cve_program_cvelist_v5
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.