Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-78265: The Events Calendar plugin lets attackers run code remotely
CVE-2026-78265 · published 10 days ago
Summary
Versions of The Events Calendar up to 6.17.2 can be tricked into loading malicious data without requiring any login. This could let an attacker execute commands on your server, potentially stealing data or disrupting services. Update the plugin to the latest version or apply the vendor's recommended patch as soon as possible.
What to do
- Update nexcess the events calendar to version 6.17.3.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| nexcess | the events calendar |
<= 6.17.2 Fix: upgrade to 6.17.3
|
Original advisory text
WordPress The Events Calendar plugin <= 6.17.2 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published24 Aug 2026
Updated30 Aug 2026
First seen24 Aug 2026
Monitor software like this
Free during beta