CRITICAL 9.8 CVE-2026-78265 Published 24 Aug 2026

The Events Calendar PHP Object Injection

Worried this affects one of your servers?

The Events Calendar plugin for WordPress is affected by an unauthenticated PHP Object Injection vulnerability in versions up to 6.17.2.

This flaw allows attackers to inject malicious PHP objects, potentially leading to remote code execution.

Reference: CVE-2026-78265 on NVD

← Back to Security News