Object Injection Vulnerability in Events Manager by Marcus
CVE-2026-57713
8.8HIGH
What is CVE-2026-57713?
The Events Manager plugin for WordPress, developed by Marcus, is susceptible to a deserialization of untrusted data vulnerability. This security flaw allows for object injection, potentially enabling an attacker to manipulate the plugin's functionality and execute arbitrary code. Users running Events Manager versions from an undefined release up to and including 7.3.6 should take immediate action to secure their installations against this risk.
Affected Version(s)
Events Manager 0 <= 7.3.6