CVE-2026-95606
Liquid Web / StellarWP The Events Calendar
Published 7 Oct 2026 · updated 7 Oct 2026 · Received
9.8 Critical · CVSS 3.1, patchstack.com
Description
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection. This issue affects The Events Calendar: from n/a through 6.17.4.