Object Injection Vulnerability in Events Manager by Marcus
CVE-2026-57713

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 July 2026

What is CVE-2026-57713?

The Events Manager plugin for WordPress, developed by Marcus, is susceptible to a deserialization of untrusted data vulnerability. This security flaw allows for object injection, potentially enabling an attacker to manipulate the plugin's functionality and execute arbitrary code. Users running Events Manager versions from an undefined release up to and including 7.3.6 should take immediate action to secure their installations against this risk.

Affected Version(s)

Events Manager 0 <= 7.3.6

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dutafi | Patchstack Bug Bounty Program
.