
🟠 CVE-2026-24954 - High Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.0.8. https://www.thehackerwire.com/vulnerability/CVE-2026-24954/ https://t.co/ZUWKGpZJZS
Post summary
A new deserialization vulnerability (CVE-2026-24954) in WpEvently allows object injection affecting versions up to 5.0.8; no PoC, exploit, or patch is mentioned.

