CRITICAL
9.8 CVE-2026-95606 Published 7 Oct 2026
The Events Calendar WordPress Plugin Object Injection Vulnerability
Worried this affects your website?
A Deserialization of Untrusted Data vulnerability has been reported in The Events Calendar by Liquid Web / StellarWP. The flaw allows Object Injection.
This issue affects The Events Calendar from n/a through 6.17.4.
Reference: CVE-2026-95606 on NVD
← Back to Security News