Skip to content
CVE-2026-95606 - Exploits & Severity

CVE-2026-95606 - Exploits & Severity

Feedly • October 7, 2026

Deserialization of untrusted data vulnerability in The Events Calendar that allows object injection attacks through the unsafe deserialization of user-supplied input.

An unauthenticated attacker over the network can exploit the deserialization vulnerability to inject malicious objects and achieve remote code execution, read sensitive data, modify data, or crash the service.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Update The Events Calendar to version 6.17.5 or later. Monitor network traffic for suspicious deserialization patterns. Consider implementing Web Application Firewall (WAF) rules to detect and block malicious serialized payloads targeting the vulnerable endpoints. Restrict access to affected plugin endpoints if possible while patches are being deployed.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

NVD published the first details for CVE-2026-95606

Feedly found the first article mentioning CVE-2026-95606 . See article

A CVSS base score of 9.8 has been assigned.

A critical deserialization vulnerability with a CVSS score of 9.8 allows for remote object injection in Liquid Web / StellarWP’s The Events Calendar, enabling attackers to manipulate application logic and potentially achieve arbitrary code execution or data exfiltration. There are currently no public proof-of-concept exploits, and the remediation status is under advisory/mitigation review. Exploitation is likely unauthenticated, requiring identification of specific input parameters that improperly handle serialized data, with potential impacts on the application and its dependencies. See article

GitHub Advisories released a security advisory .

[GHSA-39v2-8xcx-xqhh] Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Ev

CVE-2026-95606: Critical Deserialization Flaw in The Events Calendar Allows Object Injection

CVE-2026-76486: Cisco NX-OS NGOAM RCE/DoS via Crafted VXLAN OAM Packets

CVE-2026-76485: Cisco NX-OS NGOAM RCE: Unauthenticated Remote Root Code Execution or DoS

CVE-2026-95606 - Exploits & Severity - Feedly

CVE Daily Brief — 2026-10-08

Deserialization of Untrusted Data vulnerability in Liquid…

CVE-2026-76486: Cisco NX-OS NGOAM RCE/DoS via Crafted VXLAN OAM Packets

CVE-2026-76485: Cisco NX-OS NGOAM RCE: Unauthenticated Remote Root Code Execution or DoS

Be the first to know critical vulnerabilities

Collect, analyze, and vulnerability reports faster using AI