CVE-2026-95606: Liquid Web / Stellarwp The Events Calendar

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection. This issue affects The Events Calendar: from n/a through 6.17.4.

Affected products

Published 2026-10-07. Last modified 2026-10-08.