www.securityweek.com 16 Sept 2026, 11:32 UTC

Critical WordPress Calendar Flaws Put 200,000 Sites at Risk of Takeover

Critical WordPress Calendar Flaws Put 200,000 Sites at Risk of Takeover
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

MORE than 200,000 WordPress websites may be exposed to takeover attacks through two critical vulnerabilities in The Events Calendar plugin, which has more than 600,000 active installations. Defiant identified the flaws, which affect plugin versions before 6.17.3.1 and can ultimately enable unauthenticated remote code execution (RCE).

CVE-2026-78159 has a CVSS score of 9.8 and involves unauthorised code injection caused by insufficient validation. Under certain conditions, an attacker can submit a plain-array payload that bypasses checks and executes while single-event HTML is processed, including in the comment area. StellarWP fixed this issue on 25 August in version 6.17.3.1. CVE-2026-78006, also rated 9.8, is an unauthenticated PHP object-injection flaw.

It can be exploited when event comments are enabled and visible, because code submitted by an unapproved commenter reaches the vulnerable function before moderation. The developer addressed it in version 6.17.4.1, released on 10 September.

The vulnerabilities use independent exploitation chains, but Defiant says both can result in RCE and complete compromise of a WordPress installation. WordPress data indicates that about 240,000 sites were running versions earlier than 6.17, while just over 300,000 plugin downloads were recorded between 10 and 14 September, suggesting that roughly half of installations may still be exposed to CVE-2026-78006.

The precise number of vulnerable sites is unclear because exploitation of both flaws requires comments to be enabled. Site operators should update The Events Calendar to at least 6.17.4.1.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline