8.8
CVE-2026-97257
- EPSS 0.36%
- Veröffentlicht 05.10.2026 19:00:11
- Zuletzt bearbeitet 06.10.2026 15:04:25
- Erkennungen
WordPress Simple Event Planner plugin <= 1.5.7 - PHP Object Injection vulnerability
Simple Event Planner <= 1.5.7 - Authenticated (Contributor+) PHP Object Injection
Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7.
Mögliche Gegenmaßnahme
Simple Event Planner: Update to version 1.5.8, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPressTigers
≫
Produkt
Simple Event Planner
Default Statusunaffected
Version <=
1.5.7
Version
0
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Simple Event Planner
Version
*-1.5.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.36% | 0.27 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| audit@patchstack.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
https://patchstack.com/database/wordpress/plugin/simple-event-planner/vulnerability/wordpress-simple-event-planner-plugin-1-5-7-php-object-injection-vulnerability?_s_id=cve
https://www.wordfence.com/threat-intel/vulnerabilities/id/ae42c063-3889-42e1-a5d6-1dc3f17bb2c9