Critical Deserialization Vulnerability in The Events Calendar Plugin
Article Content
- •CVE-2026-95606 is a critical deserialization vulnerability with a CVSS score of 9.8.
- •The vulnerability allows remote code execution and affects all versions up to 6.17.4.
- •No public proof-of-concept or confirmed exploitation has been reported yet.
A critical deserialization of untrusted data vulnerability (CVE-2026-95606) has been identified in The Events Calendar plugin by Liquid Web / StellarWP. This flaw allows unauthenticated attackers to perform object injection, potentially leading to remote code execution, data manipulation, and denial of service. The vulnerability affects all versions up to and including 6.17.4, with a CVSS 3.1 base score of 9.8. Currently, there are no public proof-of-concept exploits or confirmed exploitation in the wild. Security experts recommend updating to version 6.17.5 or later and monitoring network traffic for suspicious patterns. The vulnerability was disclosed on 2026-10-07, and mitigation strategies are under review. Organizations are advised to restrict access to affected plugin endpoints while patches are being deployed.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-76485 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions are affected?
Is there a patch available?
What should I do if I can't patch immediately?
Continue Reading
RCE Vulnerability Discovered in Cisco Nexus 9000 Switches A vulnerability, CVE-2026-20212 (CVSS 9.8), has been identified in Cisco Nexus 9000 Series switches, allowing unauthenticated remote code execution through default TCP ports 43210 and 43211. Disclosed on September 2, 2026, during a TAC support case, the flaw affects specific product identifiers across Smart Switches…
Cisco Patches Critical RCE Vulnerabilities in NX-OS for Nexus Switches On October 7, 2026, Cisco disclosed multiple critical vulnerabilities in NX-OS affecting Nexus 3000 and 9000 Series Switches. These vulnerabilities, including CVE-2026-76465, CVE-2026-76485, CVE-2026-76486, CVE-2026-76501, and CVE-2026-76471, allow unauthenticated remote attackers to execute arbitrary code with root…