Executive brief
EventPrime, a popular WordPress plugin used for event calendar management, contains a security flaw that allows unauthorized users to inject malicious data. If exploited, an attacker could potentially take control of the website, access sensitive data, or disrupt services. This vulnerability is particularly dangerous as it does not require a login to exploit, though it may depend on specific site configurations.
Technical details
The EventPrime plugin for WordPress is vulnerable to PHP Object Injection via the deserialization of untrusted data (CWE-502). This occurs because the application fails to properly validate user-supplied input before passing it to a PHP deserialization function. An unauthenticated remote attacker can exploit this by sending a specially crafted payload. If a suitable Property-Oriented Programming (POP) chain is present in the environment, the attacker could achieve remote code execution, perform SQL injection, or conduct arbitrary file operations. The vulnerability is patched in version 4.3.2.2.
Affected products
- EventPrime EventPrime <= 4.3.2.1
Timeline
- 2026-04-25: other: Reported by researcher hhhai
- 2026-05-25: advisory: Initial advisory published by Patchstack
- 2026-06-15: disclosed: NVD publication date