๐Ÿ” CVE Alert

CVE-2025-26967

UNKNOWN 0.0

WordPress Events Calendar for GeoDirectory plugin <= 2.3.14 - PHP Object Injection vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Deserialization of Untrusted Data vulnerability in Stiofan Events Calendar for GeoDirectory events-for-geodirectory allows Object Injection.This issue affects Events Calendar for GeoDirectory: from n/a through <= 2.3.14.

CWE CWE-502
Vendor stiofan
Product events calendar for geodirectory
Published Mar 3, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for stiofan events calendar for geodirectory

Be the first to know when new unknown vulnerabilities affecting stiofan events calendar for geodirectory are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Stiofan / Events Calendar for GeoDirectory
0 โ‰ค 2.3.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/events-for-geodirectory/vulnerability/wordpress-events-calendar-for-geodirectory-plugin-2-3-14-php-object-injection-vulnerability?_s_id=cve

Credits

Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program