The Events Calendar is vulnerable to PHP Object Injection
98
Critical Risk
is_safe_widget_instance() does not stop PHP from firing magic methods during unserialize pre-parse, and enable_rendering_widget_copied() forges a valid wp_hash integrity attribute before unserialize() runs. An unauthenticated commenter can submit a crafted wp:legacy-widget block; the V2 single-event template runs do_blocks() over buffered comment HTML, and the moderation-hash URL lets the commenter view the pending comment immediately, so the payload reaches the sink before moderation. Successful exploitation leads to remote code execution. The fix hardens the widget-instance safety check so forged hashes and magic-method gadgets cannot reach unserialize().
You are affected if you are using a version that falls within the vulnerable range and comments are enabled and visible on events.
The Events Calendar is vulnerable to PHP Object Injection in versions 0.0.1 - 6.17.4.
Upgrade the The Events Calendar or the-events-calendar library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.