Description

The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.0.2 via deserialization of untrusted input from the 'filters' parameter in widgets. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code remotely. In certain configurations, this can be exploitable by lower level users. We confirmed that this plugin installed with Elementor makes it possible for users with contributor-level access and above to exploit this issue.

INFO

Published Date :

2024-08-30T06:52:15.737Z

Last Modified :

2026-04-08T16:45:51.529Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2024-8016 vulnerability.

Vendors Products
Theeventscalendar
  • Events Calendar Pro

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact