Junglewise Threat Intelligence

CVE-2026-39532: GeoDirectory Events Calendar PHP Object Injection

CVE-2026-39532 · Severity: high · CVSS 8.8 · Published 2026-06-15

Executive brief

The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to a security flaw that allows users with 'Contributor' level access to inject malicious code. This plugin is used to manage and display event listings on directory websites. If exploited, an attacker could potentially take full control of the website, access sensitive data, or disrupt services.

Technical details

A PHP Object Injection vulnerability exists in the Events Calendar for GeoDirectory plugin for WordPress (versions <= 2.3.25) due to the deserialization of untrusted data (CWE-502). The flaw allows an authenticated attacker with 'Contributor' level permissions or higher to inject a PHP object. If a suitable Property-Oriented Programming (POP) chain is present on the server, this can lead to remote code execution, SQL injection, or file system traversal. The issue is resolved in version 2.3.26.

Affected products

  • GeoDirectory Events Calendar for GeoDirectory <= 2.3.25

Timeline

  • 2026-01-11: other: Reported by researcher daroo
  • 2026-04-16: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date
  • 2026-04-16: patched: Version 2.3.26 released

References