A critical unauthenticated PHP Object Injection vulnerability has been identified in The Events Calendar WordPress plugin affecting versions up to and including 6.17.2. The vulnerability allows unauthenticated attackers to inject PHP objects, potentially leading to remote code execution or other serious security impacts. No authentication is required to exploit this vulnerability, significantly raising its risk level. The flaw has been assigned CVE-2026-78265 and is documented in both the NVD and Patchstack databases. WordPress site owners using The Events Calendar plugin should update immediately to a patched version. The vulnerability was discovered and reported through the Patchstack vulnerability disclosure program. This type of PHP Object Injection flaw can be leveraged by attackers to exploit POP (Property Oriented Programming) chains present in the application or its dependencies. The unauthenticated nature of the exploit makes it especially dangerous for any publicly accessible WordPress installation running the affected plugin versions.