Skip to content
Critical Deserialization Vulnerability in The Events Calendar Plugin

Critical Deserialization Vulnerability in The Events Calendar Plugin

First seen 8 Oct 2026, 10:38 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 11:32 UTC
  • •CVE-2026-95606 is a critical deserialization vulnerability with a CVSS score of 9.8.
  • •The vulnerability allows remote code execution and affects all versions up to 6.17.4.
  • •No public proof-of-concept or confirmed exploitation has been reported yet.

A critical deserialization of untrusted data vulnerability (CVE-2026-95606) has been identified in The Events Calendar plugin by Liquid Web / StellarWP. This flaw allows unauthenticated attackers to perform object injection, potentially leading to remote code execution, data manipulation, and denial of service. The vulnerability affects all versions up to and including 6.17.4, with a CVSS 3.1 base score of 9.8. Currently, there are no public proof-of-concept exploits or confirmed exploitation in the wild. Security experts recommend updating to version 6.17.5 or later and monitoring network traffic for suspicious patterns. The vulnerability was disclosed on 2026-10-07, and mitigation strategies are under review. Organizations are advised to restrict access to affected plugin endpoints while patches are being deployed.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-07
CVE-2026-95606 published
Liquid Web / StellarWP disclosed a critical deserialization vulnerability in The Events Calendar plugin, affecting versions up to 6.17.4.
Feedly
2026-10-07
CVE-2026-76486 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (2)

Following this threat?

Track CVE-2026-76485 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions are affected?
All versions of The Events Calendar plugin up to and including 6.17.4 are affected.
Is there a patch available?
Yes, users should update to version 6.17.5 or later to mitigate the vulnerability.
What should I do if I can't patch immediately?
Restrict access to affected plugin endpoints and monitor network traffic for suspicious activity.