Deserialization of untrusted data vulnerability in The Events Calendar that allows object injection attacks through the unsafe deserialization of user-supplied input.
An unauthenticated attacker over the network can exploit the deserialization vulnerability to inject malicious objects and achieve remote code execution, read sensitive data, modify data, or crash the service.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Update The Events Calendar to version 6.17.5 or later. Monitor network traffic for suspicious deserialization patterns. Consider implementing Web Application Firewall (WAF) rules to detect and block malicious serialized payloads targeting the vulnerable endpoints. Restrict access to affected plugin endpoints if possible while patches are being deployed.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD published the first details for CVE-2026-95606
Feedly found the first article mentioning CVE-2026-95606 . See article
A CVSS base score of 9.8 has been assigned.
A critical deserialization vulnerability with a CVSS score of 9.8 allows for remote object injection in Liquid Web / StellarWP’s The Events Calendar, enabling attackers to manipulate application logic and potentially achieve arbitrary code execution or data exfiltration. There are currently no public proof-of-concept exploits, and the remediation status is under advisory/mitigation review. Exploitation is likely unauthenticated, requiring identification of specific input parameters that improperly handle serialized data, with potential impacts on the application and its dependencies. See article
GitHub Advisories released a security advisory .
[GHSA-39v2-8xcx-xqhh] Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Ev
CVE-2026-95606: Critical Deserialization Flaw in The Events Calendar Allows Object Injection
CVE-2026-76486: Cisco NX-OS NGOAM RCE/DoS via Crafted VXLAN OAM Packets
CVE-2026-76485: Cisco NX-OS NGOAM RCE: Unauthenticated Remote Root Code Execution or DoS
CVE-2026-95606 - Exploits & Severity - Feedly
CVE Daily Brief — 2026-10-08
Deserialization of Untrusted Data vulnerability in Liquid…
CVE-2026-76486: Cisco NX-OS NGOAM RCE/DoS via Crafted VXLAN OAM Packets
CVE-2026-76485: Cisco NX-OS NGOAM RCE: Unauthenticated Remote Root Code Execution or DoS
Be the first to know critical vulnerabilities
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
