Back to Feed
VulnerabilitiesSep 16, 2026

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover

Two critical RCE flaws in The Events Calendar plugin expose 200,000+ WordPress sites.

Summary

Two critical vulnerabilities in The Events Calendar plugin, affecting versions prior to 6.17.3.1 and 6.17.4.1, could allow unauthenticated attackers to achieve remote code execution (RCE) and take over over 200,000 WordPress websites. The flaws, tracked as CVE-2026-78159 and CVE-2026-78006, are due to insufficient validation and protection mechanisms within the plugin's code processing and comment handling. StellarWP has released patches for both vulnerabilities.

Full text

More than 200,000 WordPress websites are potentially exposed to takeover attacks via two critical-severity vulnerabilities in The Events Calendar plugin. A highly popular plugin with over 600,000 active installations, The Events Calendar allows administrators to easily create and manage an events calendar on their websites. All plugin versions before 6.17.3.1 are affected by two code injection bugs that could lead to remote code execution (RCE), allowing attackers to take over sites, WordPress security firm Defiant explains. The first security defect, tracked as CVE-2026-78159 (CVSS score of 9.8), is described as an unauthenticated code injection caused by insufficient validation. Under certain conditions, an attacker can inject a plain-array payload that bypasses checks and executes during the processing of single-event HTML, including the comment area. StellarWP, The Events Calendar’s developer, patched the flaw on August 25 in version 6.17.3.1 of the plugin.Advertisement. Scroll to continue reading. Tracked as CVE-2026-78006 (CVSS score of 9.8), the second vulnerability is described as an unauthenticated PHP object injection issue that can be exploited if comments on events are enabled and visible. The security defect exists because insufficient protections in a plugin function can be bypassed by a commenter without authentication or approval, because the injected code is delivered to the vulnerable function before moderation occurs. StellarWP resolved the second flaw in The Events Calendar version 6.17.4.1, which was released on September 10. While the two security weaknesses are independent exploitation chains, both lead to RCE and the complete compromise of the WordPress installation, Defiant says. WordPress data shows that approximately 240,000 websites use The Events Calendar versions prior to 6.17, meaning that they are affected by both vulnerabilities. Between September 10 and 14, the plugin was downloaded just over 300,000 times, which suggests that roughly half of its installations may still be affected by CVE-2026-78006. It is unclear how many WordPress sites are vulnerable, as the exploitation of both critical defects requires that comments are enabled in the plugin. Related: Acronis Patches Exploited Vulnerability in cPanel Backup Plugin Related: Enterprises Warned of Attacks Exploiting WSO2 Vulnerability Related: Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases Related: $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Exein Secures $270M at $1.7B Valuation for Physical AI SecurityThai Broadband Provider Hacked via Fortinet Vulnerability240,000 Hit by Data Breach at Japan’s Digital AgencyApple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix AttackPersonal, Financial Info Exposed in Revolut Data BreachChinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code ExecutionThree JFrog Artifactory Flaws Exploited for Backdoor Deployment Latest News US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance MalwareHackuity Raises $19 Million for AI-Powered Vulnerability Management280,000 Impacted by Premier Medical Group Data BreachChrome, Firefox Updates Patch 115 VulnerabilitiesAcronis Patches Exploited Vulnerability in cPanel Backup PluginEnterprises Warned of Attacks Exploiting WSO2 VulnerabilityOracle Patches 800+ Vulnerabilities in September 2026 Security UpdateMicrosoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveGDIT has appointed retired Maj. Gen. Ryan Heritage as Vice President, Full-Spectrum Cyber.Frank Krieger has been named Chief Information Security Officer at Swap.Geoff Belknap has joined HubSpot as Chief Trust Officer.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-78159
  • cve — CVE-2026-78006

Entities

The Events Calendar (product)StellarWP (vendor)WordPress (technology)