Vulnerabilities > Theeventscalendar > Events Calendar PRO

DATE CVE VULNERABILITY TITLE RISK
2024-08-30 CVE-2024-8016 Deserialization of Untrusted Data vulnerability in Theeventscalendar Events Calendar PRO
The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.0.2 via deserialization of untrusted input from the 'filters' parameter in widgets.
network
low complexity
theeventscalendar CWE-502
7.2