513/69 Thursday, September 17, 2026

Wordfence disclosed two Critical vulnerabilities in The Events Calendar plugin for WordPress, tracked as CVE-2026-78159 and CVE-2026-78006. Both vulnerabilities have CVSS scores of 9.8 and could allow unauthenticated attackers to execute commands on the server and take control of affected websites. The plugin has more than 600,000 installations, while data from WordPress indicates that more than 240,000 websites are still using versions earlier than 6.17. However, the exact number of websites that can actually be exploited remains unclear, as exploitation requires comments to be enabled on event pages.
CVE-2026-78159 is a code injection vulnerability that could allow attackers to invoke PHP functions to change an administrator account password, then log in and upload a malicious plugin to achieve command execution. CVE-2026-78006 is a PHP object injection vulnerability that could allow attackers to execute commands on the server. The attack does not require a user account or administrator approval of comments, but the website must have comments enabled on event pages and the plugin’s “Show comments on event pages” option must be enabled.
CVE-2026-78159 affects The Events Calendar version 6.17.3 and earlier and has been fixed in version 6.17.3.1. CVE-2026-78006 affects version 6.17.4 and earlier and has been fixed in version 6.17.4.1. Website administrators should update to version 6.17.4.1 or later. If updating is not immediately possible, they should consider temporarily disabling comments on event pages to reduce the conditions required for exploitation.
