Junglewise Threat Intelligence

CVE-2026-78265: StellarWP The Events Calendar PHP object injection

CVE-2026-78265 · Severity: critical · CVSS 9.8 · Published 2026-08-24

Technologies: StellarWP The Events Calendar. Vendors: StellarWP.

Executive brief

The Events Calendar is a widely-used WordPress plugin for event management and scheduling. An unauthenticated PHP object injection flaw allows attackers to manipulate how the plugin processes data and execute arbitrary code on the server, potentially compromising the entire WordPress site and any data it contains.

Technical details

The vulnerability is a PHP object injection (CWE-502: Deserialization of Untrusted Data) in The Events Calendar plugin versions up to 6.17.2. The flaw allows unauthenticated attackers to craft malicious input that is deserialized by the plugin, enabling arbitrary code execution on the server. No authentication is required to exploit this vulnerability, and the attack vector is network-based. A fix is available in version 6.17.3 and later.

Affected products

  • StellarWP The Events Calendar <= 6.17.2

Timeline

  • 2026-08-24: disclosed: Public disclosure via NVD
  • 2026-08-24: patched: Fix available in version 6.17.3 or later

References

Related threats