CVE-2026-78265
published 2026-08-24CVE-2026-78265: Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.56%
44.7th percentile
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nexcess | the_events_calendar | n/a – 6.17.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
The Events Calendar Plugin up to 6.17.2 deserialization
vuldb·2026-08-25·CVSS 9.8
CVE-2026-78265 [CRITICAL] The Events Calendar Plugin up to 6.17.2 deserialization
A vulnerability has been found in The Events Calendar Plugin up to 6.17.2 and classified as critical. This vulnerability affects unknown code. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2026-78265. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
ghsa_unreviewed·2026-08-25
CVE-2026-78265 [CRITICAL] CWE-502 Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-24
Published