CVE-2026-95606: Liquid Web / Stellarwp The Events Calendar
Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection. This issue affects The Events Calendar: from n/a through 6.17.4.
Affected products
- Liquid Web / Stellarwp The Events Calendar: up to and including 6.17.4
Published 2026-10-07. Last modified 2026-10-08.