CyberRota Analysis
AI-GeneratedThe vulnerability allows unauthenticated PHP Object Injection in The Events Calendar versions 6.17.2 and earlier, potentially enabling attackers to execute arbitrary code on affected systems. This critical flaw poses a significant risk to any organization using these versions of the plugin, particularly those that manage event-related data. Organizations should prioritize patching or upgrading to mitigate the risk of exploitation.
CVE
CVE-2026-78265
Severity
CRITICAL
CVSS
9.8
EPSS
0.31%
Original NVD Description
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.