CRITICAL 9.8 CVE-2026-95606 Published 7 Oct 2026

The Events Calendar WordPress Plugin Object Injection Vulnerability

Worried this affects your website?

A Deserialization of Untrusted Data vulnerability has been reported in The Events Calendar by Liquid Web / StellarWP. The flaw allows Object Injection.

This issue affects The Events Calendar from n/a through 6.17.4.

Reference: CVE-2026-95606 on NVD

← Back to Security News