CVE-2026-78265

WordPress The Events Calendar plugin <= 6.17.2 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.


We have discovered 94,385 live websites that are affected by CVE-2026-78265.

Run a Free Instant Scan




Affected Software

Product  The Events Calendar
Category Wordpress Plugins
Vulnerable Domains94,385 live websites (100% of The Events Calendar install base)
Vulnerable Versions
  • from 0 through 6.17.2
Vulnerable Versions Count351 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-502 Deserialization of Untrusted Data



Details

  • Published - Aug 24, 2026
  • Updated - Aug 25, 2026

Credits

  • Udin Chan | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-78265
United States34,771 websites



Germany14,918 websites
France5,343 websites
GB4,183 websites
Netherlands3,504 websites
Italy3,209 websites
Canada2,940 websites
Spain2,443 websites
Switzerland1,884 websites
Denmark1,536 websites

Website Distribution by TLD

Number of websites using CVE-2026-78265
.com26,482 websites
.org19,105 websites
.de11,434 websites
.nl3,337 websites
.fr2,621 websites
.it2,422 websites
.ca1,803 websites
.co.uk1,764 websites
.net1,690 websites
.ch1,657 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-78265

Top websites that are affected by CVE-2026-78265. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.*******.org United States*,***
**********.com United States*,***
*****.org United States*,***
******.com United States**,***
*****.**.uk United States**,***
************.com United States**,***
*************************.de Germany**,***
***.org United States**,***
*************.edu United States**,***
*******.org United States**,***
See full domain list

FAQ

CVE-2026-78265 is Deserialization of Untrusted Data in The Events Calendar
A total of 94,385 websites have been identified as vulnerable to CVE-2026-78265, based on global website indexing conducted by WebTechSurvey.
The The Events Calendar is affected by the CVE-2026-78265 vulnerability.
The Events Calendar versions up to and including 6.17.2 are vulnerable to CVE-2026-78265.